# #forensics — MDRSS hashtag feed

> Public MDRSS cards tagged #forensics.
> Canonical feed: https://mdrss.com/feeds/forensics

## Cards (14)

### [Protocol Reverse Engineering](https://mdrss.com/security/forensics-and-reverse-engineering/901419/901419.md)

Comprehensive techniques for capturing, analyzing, and documenting network protocols for security research, interoperability, and debugging. Use it to give an agent explicit responsibilities, steps and constraints.

Classification: security/forensics-and-reverse-engineering · Feed: security · Updated: 2026-08-04T13:54:51.641Z · Version: 1

### [Memory Forensics](https://mdrss.com/security/forensics-and-reverse-engineering/901418/901418.md)

Comprehensive techniques for acquiring, analyzing, and extracting artifacts from memory dumps for incident response and malware analysis. Use it to give an agent explicit responsibilities, steps and constraints.

Classification: security/forensics-and-reverse-engineering · Feed: security · Updated: 2026-08-04T13:54:51.641Z · Version: 1

### [Binary Analysis Patterns](https://mdrss.com/security/forensics-and-reverse-engineering/901417/901417.md)

Comprehensive patterns and techniques for analyzing compiled binaries, understanding assembly code, and reconstructing program logic. Use it to give an agent explicit responsibilities, steps and constraints.

Classification: security/forensics-and-reverse-engineering · Feed: security · Updated: 2026-08-04T13:54:51.641Z · Version: 1

### [anti-reversing-techniques — detailed patterns and worked examples](https://mdrss.com/security/forensics-and-reverse-engineering/901416/901416.md)

For advanced VM detection (RDTSC delta calibration, VMware backdoor port, hypervisor leaf enumeration, guest driver artifact checks), see references/advanced-techniques.md. Use it to give an agent explicit responsibilities, steps and constraints.

Classification: security/forensics-and-reverse-engineering · Feed: security · Updated: 2026-08-04T13:54:51.641Z · Version: 1

### [Reverse engineer](https://mdrss.com/security/forensics-and-reverse-engineering/901415/901415.md)

You are an elite reverse engineer with deep expertise in software analysis, binary reverse engineering, and security research. You operate strictly within authorized contexts: security research, CTF competitions, authorized penetration testing, malware defense, and educational pu. Use it to give an agent explicit responsibilities, steps and constraints.

Classification: security/forensics-and-reverse-engineering · Feed: security · Updated: 2026-08-04T13:54:51.641Z · Version: 1

### [Malware analyst](https://mdrss.com/security/forensics-and-reverse-engineering/901414/901414.md)

You are an elite malware analyst focused on defensive security research. Your purpose is to help security professionals understand malicious software to protect systems and respond to incidents. You operate strictly within defensive and educational contexts. Use it to give an agent explicit responsibilities, steps and constraints.

Classification: security/forensics-and-reverse-engineering · Feed: security · Updated: 2026-08-04T13:54:51.641Z · Version: 1

### [Firmware analyst](https://mdrss.com/security/forensics-and-reverse-engineering/901413/901413.md)

You are an elite firmware analyst with deep expertise in embedded systems security, IoT device analysis, and hardware reverse engineering. You operate within authorized contexts: security research, penetration testing with authorization, CTF competitions, and educational purposes. Use it to give an agent explicit responsibilities, steps and constraints.

Classification: security/forensics-and-reverse-engineering · Feed: security · Updated: 2026-08-04T13:54:51.641Z · Version: 1

### [on-call-handoff-patterns — templates and worked examples](https://mdrss.com/security/forensics-and-reverse-engineering/901323/901323.md)

1. API latency around 02:00-03:00 UTC (backup window) 2. Auth service memory (restart if 80%). Use it to give an agent explicit responsibilities, steps and constraints.

Classification: security/forensics-and-reverse-engineering · Feed: security · Updated: 2026-08-04T13:54:51.641Z · Version: 1

### [Incident Runbook Templates](https://mdrss.com/security/forensics-and-reverse-engineering/901322/901322.md)

Production-ready templates for incident response runbooks covering detection, triage, mitigation, resolution, and communication. Use it to give an agent explicit responsibilities, steps and constraints.

Classification: security/forensics-and-reverse-engineering · Feed: security · Updated: 2026-08-04T13:54:51.641Z · Version: 1

### [Intelligent Issue Resolution Orchestrator](https://mdrss.com/security/forensics-and-reverse-engineering/901321/901321.md)

You MUST follow these rules exactly. Violating any of them is a failure. Use it to give an agent explicit responsibilities, steps and constraints.

Classification: security/forensics-and-reverse-engineering · Feed: security · Updated: 2026-08-04T13:54:51.641Z · Version: 1

### [Incident Response Orchestrator](https://mdrss.com/security/forensics-and-reverse-engineering/901320/901320.md)

You MUST follow these rules exactly. Violating any of them is a failure. Use it to give an agent explicit responsibilities, steps and constraints.

Classification: security/forensics-and-reverse-engineering · Feed: security · Updated: 2026-08-04T13:54:51.641Z · Version: 1

### [Incident responder](https://mdrss.com/security/forensics-and-reverse-engineering/901319/901319.md)

You are an incident response specialist with comprehensive Site Reliability Engineering (SRE) expertise. When activated, you must act with urgency while maintaining precision and following modern incident management best practices. Use it to give an agent explicit responsibilities, steps and constraints.

Classification: security/forensics-and-reverse-engineering · Feed: security · Updated: 2026-08-04T13:54:51.641Z · Version: 1

### [Digital Forensics: Tools, Methods and Workflows](https://mdrss.com/security/forensics-and-reverse-engineering/901094/901094.md)

Digital Forensics is the process of recovering and preserving material found on digital devices during the course of criminal investigations. Digital forensics tools include hardware and software tools used by law enforcement to collect and preserve digital evidence and support o. Use it to build a structured path from fundamentals to hands-on practice.

Classification: security/forensics-and-reverse-engineering · Feed: security · Updated: 2026-08-04T13:54:51.641Z · Version: 1

### [Awesome Threat Detection and Hunting](https://mdrss.com/security/forensics-and-reverse-engineering/901000/901000.md)

A curated reference on forensics & reverse engineering centered on Awesome Threat Detection and Hunting. Use it as a repeatable review, validation or hardening pass.

Classification: security/forensics-and-reverse-engineering · Feed: security · Updated: 2026-08-04T13:54:51.641Z · Version: 1
