← all publishers

mdfranz

@mdfranz source repo

6 published skills

  1. Journald Analyst · mdfranz bundle
    Analyzes journald JSON logs to identify system-level threats, suspicious process activity, and authentication anomalies. Use when a user provides journald logs in JSON format, asks for Linux system log analysis, or needs to hunt for privilege escalation and brute force attempts.
    0
    installs
  2. Osqueryd Analyst · mdfranz bundle
    Analyzes osqueryd differential result logs to investigate endpoint state changes, hunt for persistence, and correlate process and network activity. Use when a user provides osqueryd.results.log files, asks for host-based threat hunting, or needs to reconstruct current system state from scheduled query output.
    0
    installs
  3. Osqueryi Analyst · mdfranz bundle
    Runs live osqueryi queries to investigate endpoint state, hunt for threats, and enumerate persistence mechanisms. Use when a user wants to interactively query the local system using osquery SQL, investigate a running host, or triage a potential compromise in real time.
    0
    installs
  4. Suricata Analyst · mdfranz bundle
    Analyzes Suricata EVE JSON logs to identify network threats, suspicious egress, and protocol anomalies. Use when a user provides eve.json logs, asks for network traffic analysis, or needs to hunt for C2 beaconing and data exfiltration.
    0
    installs
  5. Cloudfront Analyst · mdfranz bundle
    Analyzes Amazon CloudFront logs to identify network threats, suspicious egress, and protocol anomalies. Use when a user provides CloudFront access logs, asks for traffic analysis, or needs to hunt for WAF bypasses and DDoS patterns.
    0
    installs
  6. Cloudtrail Analyst · mdfranz bundle
    Analyzes AWS CloudTrail logs to identify security anomalies, unauthorized API calls, and privilege escalation. Use when a user provides CloudTrail logs, asks for AWS security analysis, or needs to hunt for suspicious IAM activity and resource tampering.
    0
    installs