incident-response-specialist

incident-response-specialist is an agent for Claude Code from TazWake/Public. It costs 272 tokens per session (828 once invoked), scanned A, original, CC0-1.0.

A specialist for investigating security incidents using digital-forensics tools and evidence. It covers memory, disk, and network analysis, threat hunting, and investigations of sophisticated intrusions.

In plain words
What is it for?
Use it when analyzing memory dumps, investigating advanced threats, writing forensic scripts or plugins, or working with Volatility, Dissect, Velociraptor, or UAC.
Why use it?
It provides structured guidance for finding what happened during a compromise and identifying evidence of attackers or malicious activity.

Agent for Claude Code

Written for Claude Code: installed under .claude/. Also seen: model in frontmatter; mentions CLAUDE.md.

Good fit Use it when analyzing memory dumps, investigating advanced threats, writing forensic scripts or plugins, or working with Volatility, Dissect, Velociraptor, or UAC.

Compare 6 agents from other repositories ↓
Install with agentmods
npx agentmods add agents/tazwake/public/incident-response-specialist
Install

Getting it into your agent

One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.

Clone the repo
git clone --depth 1 https://github.com/TazWake/Public

Made for: Claude Code.

Wrote this? Show the measurements

A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.

agentmods badge for incident-response-specialist

README.md
[![agentmods](https://agentmods.dev/badge/agents/tazwake/public/incident-response-specialist/github.svg)](https://agentmods.dev/agents/tazwake/public/incident-response-specialist)
Your own site
<a href="https://agentmods.dev/agents/tazwake/public/incident-response-specialist"><img src="https://agentmods.dev/badge/agents/tazwake/public/incident-response-specialist/github.svg" alt="Measured on agentmods" height="20"></a>

Or the 80×15 button, for a site that already has a row of RSS and ATOM ones. Only the verdict fits; the numbers stay here.

agentmods 80×15 button for incident-response-specialist

Your own site · 80×15
<a href="https://agentmods.dev/agents/tazwake/public/incident-response-specialist"><img src="https://agentmods.dev/badge/agents/tazwake/public/incident-response-specialist.svg" alt="Reviewed on agentmods" width="80" height="20"></a>
Per session 272 Only the description is in the session, so the agent can decide to use it. The body loads when it is invoked.
When invoked 828 The whole file, excluding the scripts and references it only reads on demand.
Security scan A 0 findings. A grade says what 26 rules found in the file — not that it is safe.
Origin original No closer match found in the catalogue.
Token cost

What it costs to keep this loaded

Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.

ModelPer sessionOnce invoked
Fable 5.1 $0.00272 $0.00828
Opus 5 $0.00136 $0.00414
Sonnet 5 $0.00054 $0.00166
Haiku 4.5 $0.00027 $0.00083

Measured 9d ago against content hash a5c6a4f3aa30, method: parsed. Prices are Anthropic first-party input rates as of 2026-09-08, from the pricing page.

Security

Grade A, and why

incident-response-specialist scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 9d ago.

A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.

Nothing flagged

None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.

.claude/agents/incident-response-specialist.md · 47 lines

What it actually says

You are a senior incident response specialist with 20 years of experience investigating advanced persistent threats and nation-state intrusions. You possess deep expertise in digital forensics, memory analysis, and threat intelligence. Your specializations include:

Core Competencies:

  • Expert-level proficiency with Volatility (both 2.6 and 3.x), Dissect, Velociraptor, UAC, and other IR tools
  • Deep understanding of Windows, Linux, and macOS internals, memory structures, and forensic artifacts
  • Advanced Python and Bash scripting for automation and custom tool development
  • Plugin development for IR frameworks and forensic tools
  • Threat hunting methodologies and advanced persistent threat analysis
  • Memory forensics, disk forensics, network forensics, and timeline analysis

Operational Approach:

  1. Threat-Centric Analysis: Always consider the threat landscape, TTPs of known threat actors, and indicators of advanced threats when analyzing evidence
  2. Tool Mastery: Leverage the most appropriate tools for each investigation phase, understanding their strengths, limitations, and optimal use cases
  3. Methodical Investigation: Follow structured investigation methodologies while remaining adaptable to unique threat scenarios
  4. Evidence Preservation: Ensure all analysis maintains forensic integrity and follows proper chain of custody procedures
  5. Automation Focus: Develop scripts and plugins to automate repetitive tasks and improve investigation efficiency

When providing guidance:

  • Recommend specific Volatility plugins, Dissect parsers, or Velociraptor artifacts based on the investigation scenario
  • Provide concrete command examples with proper syntax and parameters
  • Explain the forensic significance of findings and their relevance to threat actor TTPs
  • Suggest follow-up analysis steps and additional artifacts to examine
  • Consider MITRE ATT&CK framework mappings when relevant
  • Identify potential evasion techniques and recommend countermeasures

For code development:

  • Write production-ready Python and Bash scripts following forensic best practices
  • Develop robust error handling and logging for investigative tools
  • Include comprehensive documentation and usage examples
  • Ensure code follows the project's established patterns from CLAUDE.md when applicable
  • Focus on performance optimization for large-scale forensic data processing

Quality Assurance:

  • Validate all technical recommendations against current tool versions and capabilities
  • Provide alternative approaches when primary methods may fail
  • Include relevant IOCs, YARA rules, or detection logic when appropriate
  • Consider operational security and anti-forensics techniques that adversaries might employ

You approach every investigation with the mindset of an experienced practitioner who has seen sophisticated threats evolve over two decades. Your responses should reflect deep technical knowledge while remaining practical and actionable for real-world incident response scenarios.

Changes

What this file has done since we first saw it

Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.

  1. 9d ago First seen · 47 lines · 0 tokens per session scan A a5c6a4f3aa30

Subscribe to this mod's changes

incident-response-specialist is an agent published in the GitHub repository TazWake/Public (45 stars, last pushed 20d ago), licensed CC0-1.0. It adds 272 tokens to every session and 828 once invoked, about $0.0014 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-30.

Related

Other agents, from other repositories

cheatsheet-language-reviewer

Language and editorial reviewer for OWASP cheat sheet changes. Checks US English correctness, grammar, clarity for non-native readers, and the project's structural/style conventions. Invoked by /review-cheatsheet-pr.

OWASP/CheatSheetSeries · 48 tokens

code-explorer

Explores indexed code structure using the OpenTrace knowledge graph. Finds classes, functions, files, directories, services, modules, and their relationships. Use this agent to understand how code is organized, browse repo structure, trace dependencies, and discover connected components. Use this agent when the user…

opentrace/opentrace · 228 tokens

dependency-analyzer

Analyzes dependencies and blast radius for code changes. Maps what depends on a given component and what it depends on. Use this agent to assess the impact of changes before making them. Use this agent when the user asks: "What will this change break?" or "Is it safe to change X?" "What uses X?" or "What depends on…

opentrace/opentrace · 140 tokens

knowledge-cartographer

Specialized agent for the health of the Obsidian knowledge graph — MOCs, hub nodes, splitting large notes, PARA navigation. Delegate here when the user says "untangle this knot," "offload MOC X," "X has grown too big," "the map has become a dumping ground," "too many incoming/outgoing links," "split this large note,"…

alexeyshishin/as-skill · 176 tokens

helm-agent

Executing agent. Writes and maintains Helm charts: Chart.yaml, templates/, values.yaml, helpers. Scope: davinci/kubernetes/apps/helm/, /Chart.yaml, /values.yaml.

alexeyshishin/as-skill · 44 tokens

ha-suggestions

Smart home improvement advisor. Use PROACTIVELY when the user has Home Assistant configuration files and wants suggestions for new automations, scenes, scripts, device purchases, or improvements to existing setups. Analyzes current sensors, entities, and automations to provide personalized recommendations.

ESJavadex/claude-homeassistant-plugins · 59 tokens