mdfranz
- 6 skills
- 0 followers
- 8 hours ago last updated
- ▌ Journald Analyst · mdfranz bundleAnalyzes journald JSON logs to identify system-level threats, suspicious process activity, and authentication anomalies. Use when a user provides journald logs in JSON format, asks for Linux system log analysis, or needs to hunt for privilege escalation and brute force attempts.
- ▌ Osqueryd Analyst · mdfranz bundleAnalyzes osqueryd differential result logs to investigate endpoint state changes, hunt for persistence, and correlate process and network activity. Use when a user provides osqueryd.results.log files, asks for host-based threat hunting, or needs to reconstruct current system state from scheduled query output.
- ▌ Osqueryi Analyst · mdfranz bundleRuns live osqueryi queries to investigate endpoint state, hunt for threats, and enumerate persistence mechanisms. Use when a user wants to interactively query the local system using osquery SQL, investigate a running host, or triage a potential compromise in real time.
- ▌ Suricata Analyst · mdfranz bundleAnalyzes Suricata EVE JSON logs to identify network threats, suspicious egress, and protocol anomalies. Use when a user provides eve.json logs, asks for network traffic analysis, or needs to hunt for C2 beaconing and data exfiltration.
- ▌ Cloudfront Analyst · mdfranz bundleAnalyzes Amazon CloudFront logs to identify network threats, suspicious egress, and protocol anomalies. Use when a user provides CloudFront access logs, asks for traffic analysis, or needs to hunt for WAF bypasses and DDoS patterns.
- ▌ Cloudtrail Analyst · mdfranz bundleAnalyzes AWS CloudTrail logs to identify security anomalies, unauthorized API calls, and privilege escalation. Use when a user provides CloudTrail logs, asks for AWS security analysis, or needs to hunt for suspicious IAM activity and resource tampering.