Log Analyst — Security agent for Claude Code
Security log analysis specialist.
How to install Log Analyst
Installs to ~/.claude/agents/mukul975-threatswarm-log-analyst.md
mkdir -p ~/.claude/agents && curl -fsSL https://raw.githubusercontent.com/mukul975/Threatswarm/HEAD/.claude/agents/log-analyst.md -o ~/.claude/agents/mukul975-threatswarm-log-analyst.md Restart Claude Code, or start a new session, for it to be picked up.
What Log Analyst does
name: log-analyst description: Security log analysis specialist. Parses and correlates auth.log, nginx/apache access logs, Windows Event Logs, syslog, audit logs, and cloud logs for anomalies, intrusions, and security events. Generates timeline and Sigma rules from findings. Triggers on: log analysis, log parsing, auth.log, access log, SIEM, event log, anomaly detection, log correlation, wevtutil, log forensics. tools: Bash, Read, Write, Grep, Glob model: sonnet
Cybersecurity Skills
Alternatives in Security
- JS Error Handler Auditor — Use this agent when you need to audit a JavaScript codebase for unhandled errors in top-level async operations 6.1k ★
- Aspm Correlator — Application Security Posture Management persona 548 ★
- Authz Auditor — Phase 6 authorization and access-control audit agent that enumerates every route/handler/consumer across the c 125 ★
Full documentation available on GitHub
View Source RepositoryRelated Agents
Calendar Audit
Use this agent to review calendar events, log what happened, and handle rescheduling. Can run daily or cover m
Listener Agent
Creates event listeners that react to domain events — same-BC side effects (projections, audit), cross-BC reac
Audit Logs
Query and manage Datadog Audit Trail events for compliance, security auditing, and tracking user actions acros
Ext Attack Planner
Reasons from an external-pentest inventory to the most likely footholds in an authorized engagement. Correlate
Team Finisher
Final cleanup specialist. Removes all console.log statements (including audit diagnostic logs) and enforces co
Container Attacker
Container and Kubernetes security specialist. Handles Docker escape techniques, Kubernetes RBAC abuse, service
Related Skills
Payment Intelligence Agent
Cloud-native, event-driven payment transaction intelligence agent. Ingests simulated payment events, detects a
Log Triage
Triage application logs and find the root cause fast. Multi-format parser (JSON/syslog/nginx/Python-Java stack
Grep Jsonl
Inspect Mori's ~/.mori/logs/mori-YYYY-MM-DD.jsonl event log to diagnose user-reported issues — find errors, tr