Skip to main content
Exécutez n'importe quel Skill dans Manus
en un clic

investigation-theory

Étoiles2
Forks0
Mis à jour30 mai 2026 à 19:15

Unified SOC / DFIR workflow rooted in Investigation Theory (Diagnostic Inquiry): six-stage loop, question taxonomy (preceding / context / succeeding / proximate / capability-matching / utility), GAPSS data manipulation, three-tier escalation, modified CJCSM 6510 dispositions, Once Upon a Time compromise report, Security M&M peer review, and five standard draw.io diagrams. Triggers on alert triage, log analysis (proxy / mail / Windows / Sysmon / EDR / NetFlow), phishing, lateral movement, C2 / beaconing, data exfiltration, malware execution, insider threats, and on requests to write case notes, playbooks, attack timelines, dispositions, compromise reports, or run an M&M peer review. Also fires on prompts like "help me investigate this alert", "how do I analyze these logs", "build me a playbook for X", "what questions should I ask", "document this incident", or mentions of SOC workflows, triage queues, or incident severity. Does not fire on detection engineering or offensive / red-team work.

Installation

Installer avec Codex ou Claude Copiez ce prompt, collez-le dans Codex, Claude ou un autre assistant, puis laissez-le vérifier la page du skill et l'installer pour vous.

Explorateur de fichiers
13 fichiers
SKILL.md
readonly