security-investigation

Correlate EDR, auth, network, and app logs into a security investigation timeline.

6|Updated May 30, 2026
One-click install
npx skills add https://github.com/jassics/awesome-claude-security --skill security-investigation
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: security-investigation
Source: https://github.com/jassics/awesome-claude-security/tree/main/plugins/security-analyst/skills/security-investigation
Command: npx skills add https://github.com/jassics/awesome-claude-security --skill security-investigation

SYSTEM DOCUMENTATION & REQUIREMENTS

💡 This Skill includes scripts (resource) and references (resource) and assets (resource) components.

What problem does it solve?

This Skill enables in-depth security investigations, turning multiple data sources into a coherent timeline and analysis.

Core Features & Use Cases

  • Hypothesis-Driven Analysis: Start from a lead or hypothesis and correlate evidence across sources to reach a conclusion.
  • Cross-Source Correlation: Aggregate and correlate data from EDR, auth, network, and app logs.
  • Intel Enrichment: Add threat intelligence and user/asset context to findings.
  • Timeline Reconstruction: Create a chronological narrative of events for accurate analysis.
  • Scope and Impact Analysis: Assess the full impact and lateral movement within the environment.
  • Verdict and Reporting: Reach a definitive conclusion and produce a detailed report with actionable recommendations.

Quick Start

/security-investigation: investigate the security breach of "CompanyX" using evidence from multiple sources and intel.

Frequently Asked Questions about security-investigation

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I reconstruct a security incident timeline from multiple log sources?

Timeline reconstruction aggregates logs from EDR, auth, network, and app sources. It correlates events chronologically to build a cohesive narrative, accurately mapping the breach scope and lateral movement for final analysis.

What is hypothesis-driven security investigation and when do I need it?

Hypothesis-driven security investigation starts from a specific lead and correlates evidence across multiple sources to reach a definitive conclusion. It is necessary for complex breaches or escalated cases requiring deep cross-source data correlation.

How do I correlate EDR and network logs for a breach investigation?

Cross-source correlation aggregates EDR, network, auth, and app logs into a unified dataset. It enriches findings with threat intelligence and user or asset context, enabling accurate analysis of lateral movement and full impact scope.

Can I assess lateral movement scope using correlated security evidence?

Yes, scope and impact analysis uses correlated evidence to assess lateral movement within the environment. It aggregates intelligence and reconstructs event timelines to identify compromised assets and the full extent of the breach.

Does security investigation work for escalated breach cases?

Security investigation is specifically designed for escalated cases or complex breaches. It automates evidence aggregation, intelligence correlation, and timeline reconstruction, providing a final report with a conclusion and actionable recommendations.

How do I generate a security investigation report with actionable recommendations?

Verdict and reporting reaches a definitive conclusion from correlated evidence and produces a detailed report. It includes actionable recommendations derived from timeline reconstruction, scope analysis, and intelligence enrichment findings.