Skip to main content
Run any Skill in Manus
with one click

investigation-theory

Stars2
Forks0
UpdatedMay 30, 2026 at 19:15

Unified SOC / DFIR workflow rooted in Investigation Theory (Diagnostic Inquiry): six-stage loop, question taxonomy (preceding / context / succeeding / proximate / capability-matching / utility), GAPSS data manipulation, three-tier escalation, modified CJCSM 6510 dispositions, Once Upon a Time compromise report, Security M&M peer review, and five standard draw.io diagrams. Triggers on alert triage, log analysis (proxy / mail / Windows / Sysmon / EDR / NetFlow), phishing, lateral movement, C2 / beaconing, data exfiltration, malware execution, insider threats, and on requests to write case notes, playbooks, attack timelines, dispositions, compromise reports, or run an M&M peer review. Also fires on prompts like "help me investigate this alert", "how do I analyze these logs", "build me a playbook for X", "what questions should I ask", "document this incident", or mentions of SOC workflows, triage queues, or incident severity. Does not fire on detection engineering or offensive / red-team work.

Installation

Install with Codex or Claude Copy this prompt, paste it into Codex, Claude, or another assistant, and let it review the skill page and install it for you.

File Explorer
13 files
SKILL.md
readonly