Infra Threat Detection — Security agent for Claude Code
Active alert triage and telemetry correlation.
How to install Infra Threat Detection
Installs to ~/.claude/agents/mfrostbutter-infra-ai-it-team-runbook-infra-threat-detection.md
mkdir -p ~/.claude/agents && curl -fsSL https://raw.githubusercontent.com/Mfrostbutter/Infra-AI-IT-Team-Runbook/HEAD/agents/infra-threat-detection.md -o ~/.claude/agents/mfrostbutter-infra-ai-it-team-runbook-infra-threat-detection.md Restart Claude Code, or start a new session, for it to be picked up.
What Infra Threat Detection does
name: infra-threat-detection description: Active alert triage and telemetry correlation. Reads SIEM alerts and the central journal, correlates across domains, generates incident hypotheses. Peer to infra-security. tools: Read, Bash, Glob, Grep, WebFetch model: sonnet
You own the active-threat triage domain.
Scope
- SIEM alert triage at
level >= 7(or your configured threshold) - Telemetry correlation: alerts × journal entries × host inventory
- Indicator analysis: file hashes, IP
Alternatives in Security
- Vault Librarian — Run vault maintenance: detect orphan notes, find broken wikilinks, validate frontmatter completeness, flag sta 4.6k ★
- Brain — Central knowledge coordinator 812 ★
- Aspm Correlator — Application Security Posture Management persona 548 ★
Full documentation available on GitHub
View Source RepositoryRelated Agents
Engineering Threat Detection Engineer
Expert detection engineer specializing in SIEM rule development, MITRE ATT&CK coverage mapping, threat hunting
Infra Docs
Documentation and audit specialist. Reads the central journal, runs the scheduled drift sweep, and reconciles
Oficial De Seguranca
Workbench security with dual role — (a) AUDITS every external dep/repo/AI brought by the Recruiter before adop
Infra Security
Security triage and hardening specialist. Exposure review, IR coordination, hardening recommendations. Recomme
Sovereign Filter
Decides which discovered competitors are genuinely active in UK Sovereign services (central government, defenc
Security Analyzer (Synthesizer)
You consolidate findings from research agents into prioritized hypotheses.
Related Skills
Review Observability
Audit logging, metrics, tracing, and correlation IDs across pipelines and background jobs. Flags blackbox code
Hatch3r Bug Plan
Diagnose a complex incident -- reproduce the symptom, rank root-cause hypotheses, design the fix path, and emi
Google Workspace Alert Center
Manage security alerts