用 Codex 或 Claude 帮你安装 复制这段 Prompt,粘贴到 Codex、Claude 或其他助手里,让它检查 Skill 页面并帮你完成安装。
直接命令不会经过审查 Prompt;运行前请先检查来源。
npx skills add https://github.com/jmagly/aiwg --skill forensics-hunt命令会保持在同一行。复制前请横向滚动并检查完整内容。
想先保存到本地?可下载 SkillsMP 当前能够提供的文件。
正在显示 SKILL.md
基于 SOC 职业分类
| namespace | aiwg |
| name | forensics-hunt |
| platforms | ["all"] |
| description | Threat hunt using Sigma rules against log sources |
| commandHint | {"argumentHint":"[--rules rule-id,...|all] [--target host] [--logs-path path] [--output path]","category":"forensics-hunting"} |
Perform structured threat hunting by executing Sigma detection rules against collected log sources. Supports targeted rule selection or full rule set execution. Outputs matched detections with evidence context and MITRE ATT&CK annotations.
/forensics-hunt [options]
| Argument | Required | Description |
|---|---|---|
| --rules | No | Rule IDs to run, comma-separated, or all (default: all) |
| --target | No | Target hostname to scope the hunt |
| --logs-path | No | Path to collected logs directory (default: .aiwg/forensics/acquisition/logs/) |
| --output | No | Output path (default: .aiwg/forensics/analysis/hunt-findings.md) |
| --severity | No | Minimum rule severity to execute: low, medium, high, critical (default: medium) |
| --since | No | Only evaluate log entries after this timestamp |
| --format | No | Output format: markdown (default), json, sigma-results |
| --list-rules | No | List available rules without executing |
When invoked, this command:
Discover Log Sources
Load Sigma Rules
@$AIWG_ROOT/agentic/code/frameworks/forensics-complete/sigma/--rules selection or severity thresholdExecute Detections
--since timestamp if providedDetection Categories
| Category | Example Rules |
|---|---|
| Authentication | ssh-brute-force-success, password-spray, invalid-user-spikes |
| Privilege Escalation | sudo-to-root, suid-execution, new-root-session |
| Persistence | cron-modification, new-systemd-unit, authorized-key-added |
| Lateral Movement | internal-ssh-from-new-host, ssh-agent-forwarding |
| Defense Evasion | log-deletion, audit-tampering, history-cleared |
| Exfiltration | large-outbound-transfer, curl-to-external, dns-exfil |
| C2 | reverse-shell-indicators, beaconing-intervals, tunnel-traffic |
Result Enrichment
/forensics-hunt
/forensics-hunt --rules ssh-brute-force-success,sudo-to-root --target web01
/forensics-hunt --severity high
/forensics-hunt --since 2026-02-26T18:00:00Z --severity medium
/forensics-hunt --list-rules
/forensics-hunt --severity high --format json
Artifacts are saved to .aiwg/forensics/analysis/:
.aiwg/forensics/analysis/
├── hunt-findings.md # Human-readable detection results
├── hunt-findings.json # Machine-readable results
└── rule-execution-log.yaml # Which rules ran, match counts, errors
Threat Hunt: web01-2026-02-27
━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━
Log sources: auth.log, syslog, journal, audit.log (140.6 MB)
Rules loaded: 47 applicable (of 63 total, 16 skipped: missing sources)
Executing rules...
[HIGH ] ssh-brute-force-success MATCH (1 event)
[HIGH ] sudo-to-root MATCH (2 events)
[CRITICAL] cron-modification MATCH (1 event)
[HIGH ] reverse-shell-indicators MATCH (1 event)
[MEDIUM] invalid-user-spikes MATCH (847 events)
[MEDIUM] curl-to-external MATCH (3 events)
[LOW ] failed-su-attempts no match
[LOW ] password-spray no match
━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━
Detection Summary:
CRITICAL: 1 HIGH: 3 MEDIUM: 2 LOW: 0
Total detections: 6 rules matched across 855 events
--- ssh-brute-force-success (HIGH, T1110.001) ---
Match: 2026-02-26 22:29:01 Accepted publickey for deploy from 185.220.101.42 port 51823
Context: Following 847 failed attempts (22:14:33-22:29:00) from same IP
Confidence: HIGH
--- cron-modification (CRITICAL, T1053.003) ---
Match: 2026-02-26 22:33:45 crontab: deploy modified crontab for root
Context: 4 minutes after successful SSH login from attacker IP
Confidence: HIGH
Hunt complete.
Output: .aiwg/forensics/analysis/hunt-findings.md
ID Severity Category Description
────────────────────────────────────────────────────────────────────
ssh-brute-force-success HIGH Authentication Successful login after brute force
password-spray MEDIUM Authentication Many failed logins across accounts
sudo-to-root HIGH Privilege Esc. User obtained root via sudo
new-root-session HIGH Privilege Esc. Root shell opened (non-login)
cron-modification CRITICAL Persistence Crontab file modified
new-systemd-unit HIGH Persistence New systemd unit installed
authorized-key-added HIGH Persistence New SSH authorized key added
log-deletion HIGH Defense Evasion Log file deleted or truncated
reverse-shell-indicators HIGH C2 Bash/nc/python reverse shell pattern
beaconing-intervals MEDIUM C2 Regular outbound connection pattern
large-outbound-transfer HIGH Exfiltration Unusually large outbound data transfer
Hunt Summary