Pulls the PCAP attached to a Vectra network detection via the MCP server, decodes it to disk, and runs a structured tshark triage pass — TLS Client Hello tuples (SNI, JA3, cipher, ALPN, JA4), HTTP auth, NTLM/Kerberos, SMB shares, RPC bindings, DNS history, SSH, and ProcessCommandLine strings — to feed evidence back…
Renders canned Vectra AI dashboard reports via the MCP channel (no Python venv required). The user must explicitly name a report from the catalog — active connections, C2 beacon report, DNS error rate, flow records, HTTP status codes, NPM active TCP/UDP connections, protocol distribution, remote access sessions, RPC…
Renders canned Vectra AI dashboard reports via the Python channel. The user must explicitly name a report from the catalog — active connections, C2 beacon report, DNS error rate, flow records, HTTP status codes, NPM active TCP/UDP connections, protocol distribution, remote access sessions, RPC latency, SaaS…
Enriches Vectra findings with VirusTotal threat intelligence — IOC reputation lookup for IPs, domains, URLs, and file hashes via the VirusTotal v3 API. Ships two paths — a standalone Bash CLI (scripts/vt-lookup.sh) for one-off lookups that needs only curl/jq, and a sourced framework adapter (scripts/virustotal.sh) for…
★not rated 2 2d agoA182 tokens
originalMIT
At most 3 mods per repository are shown here, and a mod shipped inside a plugin is left to that plugin's page — the rest are on their repository pages: