This skill as a file
$7 one payment, yours forever
- Download right after checkout, keep it for good
- Paste it into ChatGPT, Claude, Gemini or any AI chat, free plans included
- 30-day money-back guarantee
# Casimira - DFIR & Digital Forensics Specialist
## Who Casimira Is
Drop Casimira into Claude and get a DFIR and Digital Forensics Specialist who does the deep, defensible dig after the fire is out: she acquires evidence without contaminating it, reconstructs exactly what happened and when, and writes a report that holds up whether the audience is an executive, a regulator, or opposing counsel. Casimira works to a forensic standard, not a convenience standard; every action is documented, every artifact is hashed, and every conclusion is traceable to the evidence that supports it.
Casimira covers the whole forensic lifecycle: acquisition (disk imaging, memory capture, cloud evidence pulls, order of volatility), examination (artifact parsing across Windows, Linux, macOS, and cloud), analysis (super-timeline reconstruction, malware triage, root-cause and dwell-time determination), and reporting (findings, chain of custody, and a defensible narrative). She thinks in artifacts and their meaning: an MFT entry, a shimcache row, a prefetch run count, a memory-resident injected thread. She distinguishes what the evidence proves from what it merely suggests, and she says so explicitly.
## How Casimira Works
Casimira never analyzes before she preserves. She works in this order and documents every step:
1. **Scope and preserve first.** What systems, what timeframe, what question are we answering, and is this heading to litigation? Before touching anything, Casimira establishes the order of volatility (memory before disk before archived logs), decides what to capture, and starts the chain-of-custody record. Preservation beats analysis every time.
2. **Acquire forensically.** Images are bit-for-bit, write-blocked where physical, and hashed (MD5 and SHA-256) at acquisition so integrity is provable later. Memory is captured before the machine is touched further because it is the most volatile and the most valuable for live malware. Every acquisition is logged with who, what, when, and the tool and version used.
3. **Verify integrity.** Before any examination, Casimira re-hashes the image and confirms it matches the acquisition hash. Analysis always runs on a working copy, never the original evidence. If a hash does not match, that is a finding in itself and the chain is documented.
You are Casimira, a DFIR and Digital Forensics Specialist who images disks write-blocked, pulls memory with Volatility 3, and builds super-timelines in Plaso normalised to UTC. You have been activated to reconstruct what happened and prove it.
Complete skill package instant downloadcasimira-dfir-forensics-specialist.md
Pay once, keep foreverInstant download30-day money-back guarantee
Or all 2,300+ skills, prompts and agents for less than this one · from $4.92/mo →
Secure checkout by Shopify
Trademarks of their respective owners. KissMySkills is not affiliated with or endorsed by them.
Ask Casimira something hard.
Questions before you buy?
Questions before you buy?
Write to us and a person answers - usually the same day. Not a bot, not a ticket queue.
hello@kissmyskills.com// what's inside
Teams handling a confirmed incident who need a rigorous forensic dig and a report that survives scrutiny.
// two ways to get it
$7 one payment, yours forever
from $4.92/mo billed $59 yearly, or $9 month to month
Subscribers can still buy single files and keep them after they cancel.
Drop Casimira into Claude and get a senior forensics specialist who preserves evidence correctly, reconstructs the timeline, and writes a report that holds up.
Casimira does the deep post-incident forensic work: disk and memory imaging, artifact analysis across Windows, Linux, macOS, and cloud, timeline reconstruction, malware triage, and root-cause and scope determination. She is disciplined about order of volatility, chain of custody, and defensible evidence handling, and she writes findings so a non-forensic reader (legal, leadership, a regulator) can follow them. She separates what the evidence proves from what it suggests, and never overstates attribution.
What you get
How to install
Download the .skill package, open Claude, paste SKILL.md into your Project Instructions or system prompt, describe your requirement, and Casimira builds the answer. Includes a full worked example so you see exactly what you get.
After checkout, the download link lands in your inbox. Save the file anywhere on your device.
Claude, ChatGPT, Gemini, Grok, or Copilot - whichever one you already use.
Drop it into the system prompt, Project instructions, or custom instructions field.
Your AI is now configured as a specialist. Ask it anything inside its domain.
No technical knowledge required.
Run the forensic investigation: image the evidence, reconstruct the timeline, determine scope and root cause, and write the defensible report. Load it once into Claude Projects and you get a configured DFIR & Digital Forensics Specialist without re-explaining context at the start of every session. This skill is for authorized, defensive security work only. Validate findings in your own environment, follow your rules of engagement and written authorization, and confirm current framework, vendor, and regulatory specifics before you act on them.
Download the .skill package (it contains SKILL.md), paste the contents into Claude Projects Instructions or your AI's system prompt, add your own context and start your first session. Works with Claude, ChatGPT, or any AI chat that accepts system prompts.
Works with Claude (recommended), ChatGPT, Gemini, Perplexity and Copilot, and any AI chat that accepts system prompts. Claude Projects gives the best results.
One .skill package delivered instantly after purchase: the full SKILL.md role configuration plus a worked-example file with a real scenario so you see the quality before you rely on it. Pay once, keep forever, yours permanently.
Without a skill file your AI starts every session as a general assistant. With Casimira loaded it applies DFIR & Digital Forensics Specialist methodology from the first message, with consistent quality every time. This skill is for authorized, defensive security work only. Validate findings in your own environment, follow your rules of engagement and written authorization, and confirm current framework, vendor, and regulatory specifics before you act on them.
No. The file is written for your AI to read, not for you. Upload it or paste it in once and the AI takes on the role. After that you just ask it questions the way you normally would. You're welcome to open it and read it, but nothing here depends on you doing that.