tayontech

11 mods across 1 repository, 54 stars between them.

scope-audit

01

tayontech/SCOPE

Agent

SCOPE audit orchestrator — single entry point for the full audit pipeline. Runs Python SCOPE runtime enumeration, chains attack-path reasoning, verification, defensive controls, post-processing, and dashboard generation. Invoke with /scope:audit .

54 2mo ago A 52 tokens original MIT

scope-controls

02

tayontech/SCOPE

Agent

Controls orchestrator — dispatches six subagents in two waves (org-wide issues, detections, dashboard ideas, policy, remediation in parallel; then validate), assembles results.json. Dispatched by audit orchestrator or invoked via /scope:controls [run-dir].

54 2mo ago A 57 tokens original MIT

scope-exploit

03

tayontech/SCOPE

Agent

Red team operator — context-driven permission discovery, escalation path identification with real-world research, and narrative-first attack playbooks. Standalone by default, optionally leverages audit data via --audit flag. Invoke with /scope:exploit [--audit ].

54 2mo ago A 63 tokens original MIT

scope-investigate

04

tayontech/SCOPE

Agent

SOC alert investigation assistant. Guides analysts through CloudTrail-based alert investigation in Splunk — step-by-step guided queries, investigation timelines, and IOC correlation. Invoke with /scope:investigate.

54 2mo ago A 42 tokens original MIT

tayontech/SCOPE

Skill Claude CodeCodex

Use when constructing SCOPE attack candidate chains from audit artifacts and rejecting facts that do not form attacker progressions.

54 2mo ago A 28 tokens original MIT

tayontech/SCOPE

Skill Claude CodeCodex

Use when formatting SCOPE controls detection candidates into detections.md, detections.json, dashboard-readable SPL sections, or controls-schema detection records.

54 2mo ago A 33 tokens original MIT

tayontech/SCOPE

Skill Claude CodeCodex

Use when attaching schema-valid SCOPE evidence handles to attack candidates, hops, observations, assumptions, and caveats.

54 2mo ago A 29 tokens original MIT

tayontech/SCOPE

Skill Claude CodeCodex

Use when scope-exploit has operator-approved attack paths and needs to generate the narrative red team playbook, execution steps, persistence, post-exploitation, and IAM policy JSON without detection or SOC guidance.

54 2mo ago A 46 tokens original MIT

tayontech/SCOPE

Skill Claude CodeCodex

Use when scope-investigate completes an investigation and needs a facts-only analyst summary, evidence timeline, query appendix, investigation gaps, and optional saved investigation artifact.

54 2mo ago A 36 tokens original MIT

tayontech/SCOPE

Skill Claude CodeCodex

Use when a SCOPE top-level agent starts a run and needs bounded environment knowledge, durable observations, reasoning notes, coverage gaps, and Splunk patterns before planning.

54 2mo ago A 38 tokens original MIT

tayontech/SCOPE

Skill Claude CodeCodex

Use after SCOPE evidence review, final disposition, or operator-approved save to update durable environment knowledge, observations, coverage gaps, or proposed reasoning-note improvements.

54 2mo ago A 36 tokens original MIT