Inspect the team before use
Active database publicationDigital Forensics Incident Investigation
Authorized digital-evidence preservation, endpoint and cloud artifacts, timeline and hypothesis evidence joined for qualified DFIR review.
Opens the installed OpenCorvus desktop app. The client re-downloads and re-verifies this exact revision, then asks you for an install scope. No desktop app yet? Install OpenCorvus first
Bound execution graph
Workflow and handoffs
The graph shows who owns each step and which earlier result it depends on. It explains the team's collaboration contract; it is not live task progress and does not schedule Agents from the page.
178933335 nodes- 01digital-evidence-authority-preservation-analystFreezes investigation authority, matter scope, legal hold, systems, custodians, permitted methods and evidence custody.
root - 02endpoint-memory-disk-artifact-analystExamines supplied endpoint, memory-image and disk-image artifact observations with tool and parser provenance.
root - 03network-cloud-identity-artifact-analystCorrelates supplied network, cloud-audit and identity artifacts across accounts, devices, sessions and services.
root - 04incident-timeline-hypothesis-corroboration-analystBuilds a normalized, source-preserving event timeline and tests competing incident hypotheses.
root - 05digital-forensics-incident-evidence-ownerJoins authority, endpoint, distributed artifacts and timeline hypotheses into a contradiction-preserving review pack.
← digital-evidence-authority-preservation-analyst + endpoint-memory-disk-artifact-analyst + incident-timeline-hypothesis-corroboration-analyst + network-cloud-identity-artifact-analyst
Intended scope
Use for bounded digital-forensics incident evidence without live acquisition, containment or attribution.
- Product pillarscode + work
- Agent roster5 declared roles
- Declared workflows1 complete responsibility and dependency graphs
- Full capability projection1 Skills · 3 tools · 0 MCP refs
Roles and ownership
This roster comes from the exact package. Agent identity and base role participate in the real runtime; avatars, ratings, and personas do not influence selection.
- Digital Evidence Authority and Preservation Analyst
exploreFreezes investigation authority, matter scope, legal hold, systems, custodians, permitted methods and evidence custody. - Endpoint, Memory and Disk Artifact Analyst
delegated-workerExamines supplied endpoint, memory-image and disk-image artifact observations with tool and parser provenance. - Network, Cloud and Identity Artifact Analyst
delegated-workerCorrelates supplied network, cloud-audit and identity artifacts across accounts, devices, sessions and services. - Incident Timeline, Hypothesis and Corroboration Analyst
delegated-workerBuilds a normalized, source-preserving event timeline and tests competing incident hypotheses. - Digital Forensics Incident Evidence Owner
delegated-workerJoins authority, endpoint, distributed artifacts and timeline hypotheses into a contradiction-preserving review pack.
Workflow and handoffs
The graph shows who owns each step and which earlier result it depends on. It explains the team's collaboration contract; it is not live task progress and does not schedule Agents from the page.
digital-forensics-incident-review
Digital Forensics Incident Investigation Review
Four independent evidence roots converge into an explicit qualified-review owner.
- 01digital-evidence-authority-preservation-analystFreezes investigation authority, matter scope, legal hold, systems, custodians, permitted methods and evidence custody.depends_on: []
- 02endpoint-memory-disk-artifact-analystExamines supplied endpoint, memory-image and disk-image artifact observations with tool and parser provenance.depends_on: []
- 03network-cloud-identity-artifact-analystCorrelates supplied network, cloud-audit and identity artifacts across accounts, devices, sessions and services.depends_on: []
- 04incident-timeline-hypothesis-corroboration-analystBuilds a normalized, source-preserving event timeline and tests competing incident hypotheses.depends_on: []
- 05digital-forensics-incident-evidence-ownerJoins authority, endpoint, distributed artifacts and timeline hypotheses into a contradiction-preserving review pack.depends_on: digital-evidence-authority-preservation-analyst, endpoint-memory-disk-artifact-analyst, incident-timeline-hypothesis-corroboration-analyst, network-cloud-identity-artifact-analyst
Capability scope
The full projection includes built-in, default, and package-owned references. The package-owned subset is disclosed separately and never presented as the complete permission surface.
- Full Skill projection1 unique references; 1 are the package-owned subset
- Full tool projection3 unique references; 0 are the package-owned subset
- Full MCP projection0 server/tool/prompt/resource references; 0 are the package-owned subset
- Configuration0 fields · 0 required
Version and provenance
During publication import, the website reconstructs the canonical file tree and complete display facts from the exact ZIP referenced by the signed catalog. The local Manager validates shape, identity, topology, and digest again during install.
- Identitybuiltin/digital-forensics-incident-investigation
- Version2026.08.13.1
- Package SHA-256178933333935a194824fc09aa54d08823bf0e55eb323356a1d86929f94616ba8
This record belongs to the active database publication. The importer checked it field by field against the OpenCorvus-signed catalog, exact ZIP, and content digest. The signing private key never reaches the production server; third-party publisher identity and independent review services are not open yet.
Install boundary
The page can hand this exact revision to an installed OpenCorvus client, or stream its content-addressed ZIP. Neither path installs or activates a team from the web: the client re-downloads the archive, re-verifies its bytes, digest, and shape, and requires an explicit scope.
- 01Resolve the exact revision in the website database, verify ZIP bytes and SHA-256, then hand it to the client or start the download response
- 02Recompute the digest and strictly validate the selected package during client import
- 03Require the operator to choose project or user-global scope
- 04Import atomically through the Manager and return a mutation receipt
- 05Select the installed Squad separately before the active profile changes