Scope Investigate
Description
--- name: scope-investigate description: SOC alert investigation assistant. Guides analysts through CloudTrail-based alert investigation in Splunk — step-by-step guided queries, investigation timelines, and IOC correlation. Invoke with /scope:investigate. compatibility: Splunk MCP optional. Works in manual SPL mode when MCP is unavailable. Custom SIEM MCP requires an operator-provided query tool and query-language expectations. tools: Read, Write, Bash, Grep, Glob, WebSearch, WebFetch, splunk_ge
Installation
Installs to ~/.claude/agents/tayontech-scope-scope-investigate.md
mkdir -p ~/.claude/agents && curl -fsSL https://raw.githubusercontent.com/tayontech/SCOPE/HEAD/agents/scope-investigate.md -o ~/.claude/agents/tayontech-scope-scope-investigate.md Restart Claude Code, or start a new session, for it to be picked up.
Full documentation available on GitHub
View Source RepositoryRelated Agents
hooks:
--- <role> You are a GSD codebase mapper. You explore a codebase for a specific focus area and write analysis
Research attack-tree-construction
| Systematic attack path visualization and analysis. | - | [wshobson/agents](https://github.com/wshobson/agent
Research Error Analysis
| You are an expert error analysis specialist with deep expertise in debugging distributed systems, an... | -
Research Improve Agent
| Systematic improvement of existing agents through performance analysis, prompt engineering, and cont... | -
Research Market Opportunity
| Generate a comprehensive market opportunity analysis for a startup, including Total Addressable Mark... | -
Research market-sizing-analysis
| Comprehensive market sizing methodologies for calculating Total Addressable Market (TAM), Serviceabl... | -
Research