Skip to main content

timeline-mythic

Parse Mythic export JSON into normalized timeline entries.

소스 정보

저장소
SpecterOps/skills
최근 소스 활동
2026년 5월 29일 15:51
감지된 SKILL.md 언어
영어
스타
689
포크
77

설치 방법

기본적으로 소스를 먼저 확인하는 Prompt가 선택됩니다. 직접 명령으로 전환하거나 로컬 사본을 다운로드할 수도 있습니다.

소스 파일 검토

설치 여부를 결정하기 전에 SKILL.md와 SkillsMP에 표시된 보조 파일을 읽어 보세요.

파일 탐색기
4 개 파일

SKILL.md 표시 중

SKILL.md
소스 지침 · 읽기 전용 미리보기
name
timeline-mythic
description
Parse Mythic export JSON into normalized timeline entries.
metadata
{"author":"GhostWorks"}
# Timeline Mythic Parser Trigger when Mythic exports (callbacks/tasks/responses/operations) are provided for timeline consolidation. ## Input Contract - Directory `input/c2logs/mythic/` with JSON exports for callbacks, tasks, responses, or full operations. ## Output - Produce `output/mythic_entries.json` with timeline entries (timestamp, source, operator, action, details, raw_timestamp). - Add metadata with `source_type = "mythic"`, counts, and parse errors. ## Workflow 1. Detect export type (callbacks, tasks, full operations) by inspecting keys such as `callbacks`, `command_name`, or `timestamp`. 2. Convert all timestamps to ISO 8601 UTC (ensure `Z` suffix) using `fromisoformat` fallback patterns. 3. Emit entries: - Callback exports: `beacon_init` at `init_callback`, `checkin` at `last_checkin`. - Task exports: map `command_name`, `original_params`, or `display_params` to `action`/`details`. - Operation exports: iterate nested `callbacks` and `tasks`, keeping owner context. 4. Normalize `source` names to `Mythic-callback-<id>` or `Mythic-task-<id>`. 5. Include operator names, host/service details, and `action = task_name` with `details` from params/output. 6. Capture MITRE clues from command names when available (documented in the consolidator). ## Notes - Favor `display_params` for human-readable commands. - When `responses` arrays exist, include their output as part of the `details` field.
GitHub에서 보기