tayontech

Scope Investigate — Research agent for Claude Code

Research community

SOC alert investigation assistant.

How to install Scope Investigate

Installs to ~/.claude/agents/tayontech-scope-scope-investigate.md

Terminal
mkdir -p ~/.claude/agents && curl -fsSL https://raw.githubusercontent.com/tayontech/SCOPE/HEAD/agents/scope-investigate.md -o ~/.claude/agents/tayontech-scope-scope-investigate.md

Restart Claude Code, or start a new session, for it to be picked up.

What Scope Investigate does


name: scope-investigate description: SOC alert investigation assistant. Guides analysts through CloudTrail-based alert investigation in Splunk — step-by-step guided queries, investigation timelines, and IOC correlation. Invoke with /scope:investigate. compatibility: Splunk MCP optional. Works in manual SPL mode when MCP is unavailable. Custom SIEM MCP requires an operator-provided query tool and query-language expectations. tools: Read, Write, Bash, Grep, Glob, WebSearch, WebFetch, splunk_ge

Alternatives in Research

  • Debug Agent — You are a specialized debugging agent 3.6k ★
  • Cnki Researcher — CNKI Research Assistant - helps with literature search, journal lookup, and indexing queries on CNKI (中国知网) 880 ★
  • Clawdia Assistant — Use this agent when the user needs operational and strategic support — managing agenda, emails, tasks, meeting 523 ★

Full documentation available on GitHub

View Source Repository