Scope Investigate banner
tayontech tayontech

Scope Investigate

Research community

Description

--- name: scope-investigate description: SOC alert investigation assistant. Guides analysts through CloudTrail-based alert investigation in Splunk — step-by-step guided queries, investigation timelines, and IOC correlation. Invoke with /scope:investigate. compatibility: Splunk MCP optional. Works in manual SPL mode when MCP is unavailable. Custom SIEM MCP requires an operator-provided query tool and query-language expectations. tools: Read, Write, Bash, Grep, Glob, WebSearch, WebFetch, splunk_ge

Installation

Installs to ~/.claude/agents/tayontech-scope-scope-investigate.md

Terminal
mkdir -p ~/.claude/agents && curl -fsSL https://raw.githubusercontent.com/tayontech/SCOPE/HEAD/agents/scope-investigate.md -o ~/.claude/agents/tayontech-scope-scope-investigate.md

Restart Claude Code, or start a new session, for it to be picked up.

Full documentation available on GitHub

View Source Repository