scanning-the-network

Coordinate parallel subagent investigations to generate consolidated network threat reports.

6|Updated Feb 21, 2026
One-click install
npx skills add https://github.com/skywatch-bsky/skywatch-agent-skills --skill scanning-the-network
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: scanning-the-network
Source: https://github.com/skywatch-bsky/skywatch-agent-skills/tree/main/claude-skills/plugins/skywatch-investigations/skills/scanning-the-network
Command: npx skills add https://github.com/skywatch-bsky/skywatch-agent-skills --skill scanning-the-network

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

This skill addresses the challenge of identifying emerging threats and anomalous patterns across large-scale network data by automating complex, multi-faceted investigative workflows.

Core Features & Use Cases

  • Parallel Investigation: Simultaneously executes baseline traffic analysis, rule-hit monitoring, and co-sharing/entropy detection.
  • Consolidated Reporting: Synthesizes disparate data signals into a single, actionable BLIND-style report.
  • Use Case: Use this when you suspect an uptick in coordinated activity or need to identify detection gaps following a potential security incident.

Quick Start

Use the scanning-the-network skill to perform a network-wide threat scan for the past 7 days with hourly granularity.

Frequently Asked Questions about scanning-the-network

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I perform network-wide threat hunting using ClickHouse data?

Coordinated network activity detection analyzes traffic baselines, rule hits, and entropy simultaneously to identify emerging threats. It automates parallel subagent investigations to synthesize multi-faceted network data signals into consolidated, evidence-based reports.

What is the best way to automate incident response investigations across large-scale network traffic?

Automating incident response investigations requires executing parallel subagent workflows that monitor rule hits and analyze traffic baselines. This approach synthesizes disparate network signals into a single consolidated report with evidence-based recommendations.

Does this network analysis approach require read-only access to ClickHouse and Skywatch MCP tools?

Yes, proactive network threat scanning requires read-only access to ClickHouse and Skywatch MCP tools. These tools enable querying network traffic data and generating consolidated threat reports with evidence-based recommendations.

When do I need entropy analysis for threat hunting?

Entropy analysis for threat hunting is needed when you suspect an uptick in coordinated activity or must identify detection gaps following a security incident. It applies multi-faceted investigative workflows to detect anomalous patterns across large-scale network data.

Can I scan network traffic for the past 7 days with hourly granularity?

Yes, you can perform a network-wide threat scan for the past 7 days with hourly granularity. This temporal window allows you to establish traffic baselines and monitor rule hits for incident response and threat hunting scenarios.