Detects and analyzes system threats, malware, and security vulnerabilities on Windows systems. Use for system scanning, browser hijacking detection, Windows registry analysis, suspicious file investigation, binary analysis, and threat reporting with remediation steps.
Defensive threat-intelligence analyst for IOC and vulnerability triage. Use PROACTIVELY whenever the user drops one or more indicators — an IP, domain, URL, or CVE — and wants to know if it's malicious, who's flagging it, how weaponized a CVE is, or how to prioritize it. Also use to build or refresh a local blocklist…
Use proactively after all artifact agents complete and before generatereport. Takes all findings from state.json and stress-tests each one against other artifact sources to confirm, escalate, demote, or dismiss. Applies evidence corroboration chains, stacked anomaly validation, and temporal proximity analysis. Returns…
Use proactively when summarizeevtx returns a csvpath for Security.evtx, System.evtx, or Sysmon logs. Windows event log forensic specialist covering the full attacker lifecycle - authentication anomalies, lateral movement, credential theft, persistence, defense evasion, and NTLM/Kerberos attacks. Returns condensed…