GreyCortex-investigation

Aggregate GreyCortex Mendel incidents and OT findings into a timestamped markdown report.

Updated May 5, 2026
One-click install
npx skills add https://github.com/laroy-sh/greycortex-investigation --skill greycortex-investigation
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: GreyCortex-investigation
Source: https://github.com/laroy-sh/greycortex-investigation/tree/main
Command: npx skills add https://github.com/laroy-sh/greycortex-investigation --skill greycortex-investigation

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

This Skill automates security assessments for GreyCortex Mendel deployments, turning scattered CEM and sensor data into a single actionable investigation report.

Core Features & Use Cases

  • Global posture review: Summarizes open incidents, high-severity detection events, OT-specific activity, and threat intelligence hits across the Mendel environment.
  • Per-sensor investigation: Spawns parallel analysis for each discovered sensor to examine notable events, subnet context, and unknown-host enrichment.
  • Actionable reporting: Produces a timestamped markdown assessment with prioritized findings and concrete recommendations for security teams.

Quick Start

Ask the skill to run a GreyCortex Mendel security assessment for the desired time window and sensor scope.

Frequently Asked Questions about GreyCortex-investigation

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I automate a GreyCortex Mendel security assessment report?

To automate a GreyCortex Mendel security assessment, run a read-only evaluation that aggregates incidents, detection events, OT findings, and threat intelligence into a single timestamped markdown report. This requires Mendel MCP connectivity and viewer access.

What is the best way to investigate threats across multiple Mendel sensors?

Threat investigation across multiple Mendel sensors is handled by spawning parallel analyses for each discovered sensor, examining notable events, subnet context, and unknown-host enrichment to provide per-sensor triage and prioritized findings.

Can I review OT security findings and threat intelligence in one report?

Yes, you can review OT security findings and threat intelligence in one report. The assessment aggregates OT-specific activity, threat intelligence hits, and high-severity detection events across the connected CEM deployment into an actionable markdown file.

Do I need Jina AI OUI enrichment for unknown MAC addresses in Mendel?

Yes, Jina AI OUI enrichment is required to resolve unknown MAC-addressed hosts during a Mendel security assessment. This enrichment provides necessary context for per-sensor triage and comprehensive threat investigations.

How do I perform a read-only security posture review for a Mendel deployment?

Performing a read-only security posture review involves summarizing open incidents, high-severity detection events, and threat intelligence hits across the Mendel environment, producing a timestamped markdown assessment with concrete security recommendations.

Does the Mendel security assessment modify CEM or sensor configurations?

No, the Mendel security assessment is strictly read-only. It aggregates scattered CEM and sensor data to generate an actionable investigation report without modifying any existing deployment configurations or active sensor settings.