Digital Forensics Analyst, Casimira AI skill by KissMySkills, cover

Casimira - Digital Forensics Analyst AI Skill

$7.00
Sale price  $7.00 Regular price 
Skip to product information
Digital Forensics Analyst, Casimira AI skill by KissMySkills, cover

Casimira - Digital Forensics Analyst AI Skill

$7.00 this skill one payment yours forever
// skill previewcasimira-dfir-forensics-specialist.md
# Casimira - DFIR & Digital Forensics Specialist

## Who Casimira Is
Drop Casimira into Claude and get a DFIR and Digital Forensics Specialist who does the deep, defensible dig after the fire is out: she acquires evidence without contaminating it, reconstructs exactly what happened and when, and writes a report that holds up whether the audience is an executive, a regulator, or opposing counsel. Casimira works to a forensic standard, not a convenience standard; every action is documented, every artifact is hashed, and every conclusion is traceable to the evidence that supports it.

Casimira covers the whole forensic lifecycle: acquisition (disk imaging, memory capture, cloud evidence pulls, order of volatility), examination (artifact parsing across Windows, Linux, macOS, and cloud), analysis (super-timeline reconstruction, malware triage, root-cause and dwell-time determination), and reporting (findings, chain of custody, and a defensible narrative). She thinks in artifacts and their meaning: an MFT entry, a shimcache row, a prefetch run count, a memory-resident injected thread. She distinguishes what the evidence proves from what it merely suggests, and she says so explicitly.

## How Casimira Works
Casimira never analyzes before she preserves. She works in this order and documents every step:

1. **Scope and preserve first.** What systems, what timeframe, what question are we answering, and is this heading to litigation? Before touching anything, Casimira establishes the order of volatility (memory before disk before archived logs), decides what to capture, and starts the chain-of-custody record. Preservation beats analysis every time.

2. **Acquire forensically.** Images are bit-for-bit, write-blocked where physical, and hashed (MD5 and SHA-256) at acquisition so integrity is provable later. Memory is captured before the machine is touched further because it is the most volatile and the most valuable for live malware. Every acquisition is logged with who, what, when, and the tool and version used.

3. **Verify integrity.** Before any examination, Casimira re-hashes the image and confirms it matches the acquisition hash. Analysis always runs on a working copy, never the original evidence. If a hash does not match, that is a finding in itself and the chain is documented.
Preview: lines 19 to 26 of 84 · Full file after purchase or included in Unlimited Access
Use the name
Once the file is loaded, talk to it by name: “Serge, check this page.” That is what the name is for. It also keeps several skills apart in one chat.
// the skill your AI runs on

You are Casimira, a DFIR and Digital Forensics Specialist who images disks write-blocked, pulls memory with Volatility 3, and builds super-timelines in Plaso normalised to UTC. You have been activated to reconstruct what happened and prove it.

84 lines · .md · instant download or included in Unlimited Access

Complete skill package instant downloadcasimira-dfir-forensics-specialist.md

  • American Express
  • Apple Pay
  • Bancontact
  • BLIK
  • Google Pay
  • Klarna
  • Maestro
  • Mastercard
  • MobilePay
  • PayPal
  • Union Pay
  • Visa

Secure checkout by Shopify

Trademarks of their respective owners. KissMySkills is not affiliated with or endorsed by them.

Ask Casimira something hard.

📎 casimira-dfir-forensics-specialist.md LOADED ✓
We contained a compromised laptop. Walk me through the forensics to find how they got in and what they touched.
CLAUDE · AS CASIMIRA, DIGITAL FORENSICS ANALYST Casimira returns an evidence-preservation plan in order of volatility, the specific artifacts to pull and what each proves, a reconstructed timeline, a scope and root-cause assessment separating proof from inference, and a report structure suitable for legal and leadership.

Questions before you buy?

Questions before you buy?

Write to us and a person answers - usually the same day. Not a bot, not a ticket queue.

hello@kissmyskills.com

// what's inside

What's inside this skill

  1. Disk and memory imaging with correct order of volatility
  2. Artifact analysis across Windows, Linux, macOS, and cloud
  3. Timeline reconstruction, malware triage, and scope determination
  4. Chain-of-custody discipline and defensible forensic reporting

Teams handling a confirmed incident who need a rigorous forensic dig and a report that survives scrutiny.

// two ways to get it

Buy this file, or open the whole library.

Buy once

This skill as a file

$7 one payment, yours forever

  • Download right after checkout, keep it for good
  • Paste it into ChatGPT, Claude, Gemini or any AI chat, free plans included
  • 30-day money-back guarantee
Unlimited Access

Every skill, prompt and agent, inside your chat

from $4.92/mo billed $59 yearly, or $9 month to month

  • All 2,300+ files in the library, loaded the moment you ask
  • Nothing to download or paste: connect once in Claude, ChatGPT, Claude Code or Cursor
  • Needs a paid AI plan · 14-day refund on the first charge
See Unlimited Access →

Subscribers can still buy single files and keep them after they cancel.

What you're actually buying

Drop Casimira into Claude and get a senior forensics specialist who preserves evidence correctly, reconstructs the timeline, and writes a report that holds up.

Casimira does the deep post-incident forensic work: disk and memory imaging, artifact analysis across Windows, Linux, macOS, and cloud, timeline reconstruction, malware triage, and root-cause and scope determination. She is disciplined about order of volatility, chain of custody, and defensible evidence handling, and she writes findings so a non-forensic reader (legal, leadership, a regulator) can follow them. She separates what the evidence proves from what it suggests, and never overstates attribution.

What you get

  • Disk and memory imaging with correct order of volatility
  • Artifact analysis across Windows, Linux, macOS, and cloud
  • Timeline reconstruction, malware triage, and scope determination
  • Chain-of-custody discipline and defensible forensic reporting
📄 casimira-dfir-forensics-specialist.skill Under 2 min install Works with Claude, ChatGPT & any AI chat

How to install

Download the .skill package, open Claude, paste SKILL.md into your Project Instructions or system prompt, describe your requirement, and Casimira builds the answer. Includes a full worked example so you see exactly what you get.

// how to install Under 2 minutes

Four steps. Any AI chat.

  1. 01
    Download the file

    After checkout, the download link lands in your inbox. Save the file anywhere on your device.

  2. 02
    Open your AI chat

    Claude, ChatGPT, Gemini, Grok, or Copilot - whichever one you already use.

  3. 03
    Paste the file contents

    Drop it into the system prompt, Project instructions, or custom instructions field.

  4. 04
    Start working

    Your AI is now configured as a specialist. Ask it anything inside its domain.

No technical knowledge required.

// faq

Questions about this product

What does the Casimira skill do?+

Run the forensic investigation: image the evidence, reconstruct the timeline, determine scope and root cause, and write the defensible report. Load it once into Claude Projects and you get a configured DFIR & Digital Forensics Specialist without re-explaining context at the start of every session. This skill is for authorized, defensive security work only. Validate findings in your own environment, follow your rules of engagement and written authorization, and confirm current framework, vendor, and regulatory specifics before you act on them.

How do I install this skill file?+

Download the .skill package (it contains SKILL.md), paste the contents into Claude Projects Instructions or your AI's system prompt, add your own context and start your first session. Works with Claude, ChatGPT, or any AI chat that accepts system prompts.

Which AI tools does this skill work with?+

Works with Claude (recommended), ChatGPT, Gemini, Perplexity and Copilot, and any AI chat that accepts system prompts. Claude Projects gives the best results.

What is included in this download?+

One .skill package delivered instantly after purchase: the full SKILL.md role configuration plus a worked-example file with a real scenario so you see the quality before you rely on it. Pay once, keep forever, yours permanently.

How is this different from using Claude without the Casimira skill?+

Without a skill file your AI starts every session as a general assistant. With Casimira loaded it applies DFIR & Digital Forensics Specialist methodology from the first message, with consistent quality every time. This skill is for authorized, defensive security work only. Validate findings in your own environment, follow your rules of engagement and written authorization, and confirm current framework, vendor, and regulatory specifics before you act on them.

Do I have to read it myself?+

No. The file is written for your AI to read, not for you. Upload it or paste it in once and the AI takes on the role. After that you just ask it questions the way you normally would. You're welcome to open it and read it, but nothing here depends on you doing that.

Ready to specialise your AI?