EDR Telemetry & Live Hunt Collections
CommunityTurn EDR and Velociraptor evidence into hunt intel.
Data & Analytics#threat hunting#velociraptor#network connections#edr#forensic triage#process trees#att&ck mapping
Authorrjonhaas
Version1.0.0
Installs0
System Documentation
What problem does it solve?
This Skill helps analysts quickly make sense of EDR exports and Velociraptor collection ZIPs by extracting suspicious process, network, file, persistence, and timeline signals and translating them into investigation-ready leads.
Core Features & Use Cases
- Velociraptor ZIP triage: Extracts and inventories JSON/JSONL artifacts, then derives process lists, suspicious process paths, external network connections, persistence indicators, event-log inventory, file timelines, and suspicious DLL loads.
- EDR export normalization: Applies vendor-specific field mapping for CrowdStrike, SentinelOne, Microsoft Defender for Endpoint, and supports CSV/JSON variants to produce consistent hunt outputs.
- Process-chain reconstruction: Rebuilds parent-child process chains from EDR telemetry to identify initial entry points and escalation patterns.
- ATT&CK-aligned finding recognition & pivoting: Detects common live-hunt patterns (staging execution, Office-to-shell chains, C2 connections, scheduled task/run-key persistence, orphaned processes, DLL sideloading patterns, and lsass access) and provides escalation guidance to the Investigation Section Chief (ISC) for confirmation and further domain skills.
Quick Start
Use the EDR Telemetry & Live Hunt Collections skill to analyze a case’s Velociraptor or vendor EDR export and produce process trees, external connection lists, persistence artifacts, timelines, and escalation-ready findings.
Dependency Matrix
Required Modules
None requiredComponents
Standard package💻 Claude Code Installation
Recommended: Let Claude install automatically. Simply copy and paste the text below to Claude Code.
Please help me install this Skill: Name: EDR Telemetry & Live Hunt Collections Download link: https://github.com/rjonhaas/SIFTics/archive/main.zip#edr-telemetry-live-hunt-collections Please download this .zip file, extract it, and install it in the .claude/skills/ directory.
Agent Skills Search Helper
Install a tiny helper to your Agent, search and equip skill from 471,000+ vetted skills library on demand.