원클릭으로
log-timeline-hunter
Analyzes acquired logs during an authorized incident - Windows Event Logs (EVTX, incl. Sysmon) via Chainsaw/Hayabusa with Sigma rules, Linux auth/syslog/audit, and network logs/PCAP via tshark/Zeek - to reconstruct the attack timeline and detect logon anomalies, credential attacks, lateral movement, service/task install, and C2 beaconing. Correlates into a single UTC timeline and maps events to MITRE ATT&CK (T1110, T1021, T1059, T1543, T1071). Use when log/EVTX/PCAP evidence exists in Detection & Analysis. Requires .claude/security-scope.yaml dfir_scope.incident_response: approved and evidence from dfir_scope.evidence_store_path. Read-only on evidence copies; no containment. Grounded in incident-response.
Codex 또는 Claude로 설치 이 Prompt를 복사해 Codex, Claude 또는 다른 어시스턴트에 붙여 넣으면 Skill 페이지를 검토하고 설치를 진행할 수 있습니다.