SCStelz

29 mods across 1 repository, 243 stars between them.

SCStelz/security-investigator

Skill Claude CodeCodex

Sentinel Ingestion Report — YAML-driven PowerShell pipeline gathers all data via az monitor/az rest/Graph API, writes a deterministic scratchpad, LLM renders the report. Covers table-level volume breakdown, tier classification (Analytics/Basic/Data Lake), SecurityEvent/Syslog/CommonSecurityLog deep dives, ingestion…

243 2d ago A 134 tokens original MIT

svg-dashboard

26

SCStelz/security-investigator

Skill Claude CodeCodex

Use this skill when asked to generate SVG data visualization dashboards from investigation data or skill reports. Triggers on keywords like "generate SVG dashboard", "create a visual dashboard", "visualize this report", "SVG from the report", "visualize results", "create SVG chart", "SVG from this data". Supports two…

243 2d ago A 132 tokens original MIT

SCStelz/security-investigator

Skill Claude CodeCodex

Turn a published threat-intelligence article into a tested threat-hunting campaign. Reads a platform-agnostic RSS/Atom feed (feedurl is a parameter — nothing vendor-specific is hardcoded), triages articles from a recent window, applies a huntability relevance gate to decide whether an article warrants a campaign, then…

243 2d ago A 181 tokens original MIT

threat-pulse

28

SCStelz/security-investigator

Skill Claude CodeCodex

Recommended starting point for new users and daily SOC operations. 15-minute broad security scan across 7 domains (incidents, identity, NHI, endpoint, email, admin/cloud, exposure) producing a Threat Pulse Dashboard with drill-down recommendations to specialized skills. Trigger on getting-started questions like "where…

243 2d ago A 81 tokens original MIT

user-investigation

29

SCStelz/security-investigator

Skill Claude CodeCodex

Use this skill when asked to investigate a user account for security issues, suspicious activity, or compliance review. Triggers on keywords like "investigate user", "security investigation", "user investigation", "check user activity", "analyze sign-ins", or when a UPN/email is mentioned with investigation context.…

243 2d ago A 110 tokens original MIT