Use this agent when working with Docker, Kubernetes, or any container-related tasks including building Dockerfiles, creating docker-compose configurations, troubleshooting container deployments, optimizing container performance, designing container architectures, or needing guidance on containerization best practices.…
Use this agent when you need to plan, organize, or manage cybersecurity projects and changes. This includes creating project plans, developing documentation, establishing build processes, validating deliverables, and ensuring task completion. Examples: Context: User needs to plan the implementation of a new security…
Use this agent when creating, modifying, or enhancing digital forensic tools, incident response scripts, memory analysis plugins, evidence collection utilities, or any DFIR-related automation. Examples: Context: User is developing a new Volatility plugin for detecting process hollowing. user: 'I need to create a…
Use proactively after all artifact agents complete and before generatereport. Takes all findings from state.json and stress-tests each one against other artifact sources to confirm, escalate, demote, or dismiss. Applies evidence corroboration chains, stacked anomaly validation, and temporal proximity analysis. Returns…
Use proactively when summarizeevtx returns a csvpath for Security.evtx, System.evtx, or Sysmon logs. Windows event log forensic specialist covering the full attacker lifecycle - authentication anomalies, lateral movement, credential theft, persistence, defense evasion, and NTLM/Kerberos attacks. Returns condensed…