incident-response-networkNetwork forensics evidence collection and analysis during security incidents. Guides volatile evidence preservation, lateral movement detection via flow reco...
Install via ClawdBot CLI:
clawdbot install vahagn-madatyan/incident-response-networkGrade Fair — based on market validation, documentation quality, package completeness, maintenance status, and authenticity signals.
Generated May 2, 2026
A bank detects suspicious lateral movement from a compromised employee workstation. Network engineers use this skill to collect ARP and CAM tables, start packet captures on critical segments, and verify that newly applied ACLs are blocking the attacker's traffic.
After a ransomware attack, a hospital's network team reconstructs the timeline of data exfiltration by analyzing flow records and routing table snapshots captured during and after the incident. The skill guides evidence preservation and timeline reconstruction for regulatory compliance.
A SaaS provider suspects an insider exfiltrating customer data via SSH tunnels. Using flow record analysis and packet captures on edge routers, the incident response team quantifies the volume of outbound data and identifies the specific hosts involved.
A large retailer's security team observes anomalous internal connections during peak shopping season. The skill's step-by-step procedure helps them trace the attacker's movement across VLANs using ARP/MAC changes and routing table analysis, minimizing disruption to sales operations.
Offer this skill as a retainer-based service to enterprises that lack in-house network forensics expertise. Customers pay a monthly fee for access to read-only network evidence collection and analysis during incidents.
Develop and sell online courses or workshops that teach network forensics using this skill. Generate revenue from course fees and certification exams for network security professionals.
License the skill as a plugin for commercial SIEM or SOAR products, enabling automated evidence collection playbooks. Revenue comes from licensing fees per deployment or per-incident usage.
💬 Integration Tip
Integrate with a SOAR platform to trigger evidence collection automatically upon specific alerts (e.g., malware detection or unusual flow volumes), and pipe outputs to a SIEM for correlation.
Scored Jun 27, 2026
Control remote Windows machines via SSH. Use when executing commands on Windows, checking GPU status (nvidia-smi), running scripts, or managing remote Windows systems. Triggers on "run on Windows", "execute on remote", "check GPU", "nvidia-smi", "远程执行", "Windows 命令".
Perform reverse lookup of gTLD domains hosted on a specified nameserver with optional filters by TLD and domain prefix length.
Configure OpenClaw installations with optimized settings, channel setup, security hardening, and production recommendations.
Connect to remote desktops via RDP, VNC, and SSH X11 with secure tunneling and troubleshooting.
Essential curl commands for HTTP requests, API testing, and file transfers.
Deploy and manage Vercel projects. Use when deploying applications to Vercel, managing environment variables, checking deployment status, viewing logs, or performing Vercel operations. Supports production and preview deployments. Practical infrastructure operations - no "AI will build your app" magic.