Cyber threat intelligence and OSINT analysis toolkit. Runs structured investigations and delivers analyst-grade intelligence products with sourced, trust-scored findings. Use for OSINT and CTI cases, digital-footprint and exposure review, domain/subdomain/DNS/certificate recon, web-infrastructure pivoting (favicon…
Process image files into validated CASE/UCO or CAC knowledge graphs. Use when the user provides images, receipts, screenshots, scans, photos, OCR output, or asks to convert an image file into CASE/UCO/CAC JSON-LD.
This skill should be used when the user asks to "create/scaffold a new X-Tension", "wrap a CLI tool in an X-Tension", "port a convention into an X-Tension" (helper-exe verification, Ctrl-to-save, output-dir), "audit/modernize an X-Tension", "build/compile an X-Tension", "prep an X-Tension for public release", or asks…
REQUIRED when the user says "start investigation", "investigate", "analyze case", "Read case-templates/manifest.json", references a manifest.json, or provides a SAVVYDFIR-MCP caseid. Defines the 5-phase DFIR methodology from evidence mounting through report generation, with mandatory tools, decision points, and…
Load when you have an initial finding and need to determine what to investigate next. Defines universal pivot chains from each artifact type to related evidence, enabling systematic investigation expansion.
Load when you need exact command syntax for SIFT Workstation tools. Covers Volatility 3, Sleuth Kit, EZ Tools, Plaso, YARA, and Regripper with actual invocation examples and output parsing guidance.
Use when writing or creating Sigma rules, reviewing detection rules, discussing detection coverage, or working with YAML detection files. Enforces this project's detection rule standards (ATT&CK mapping, severity justification, false positive documentation, test cases, naming conventions).
Use when ingesting threat-intelligence IOC data (native JSON lists, MISP JSON event exports), normalizing indicators to a common schema, or correlating them across sources and against this project's Sigma rule coverage. Enforces the normalized IOC schema and the v1 scope limits below.