npx claudepluginhub funnywolf/agentic-soc-platform --plugin ASPThis skill uses the workspace's default tool permissions.
当用户要围绕 artifact 进行调查分析时,使用这个 skill。
Manages ASP artifacts for cyber investigations: find by IOC/filters, create new ones, attach to alerts, save enrichments.
Guides use of SentinelOne Purple AI for natural language cybersecurity investigations, threat hunting, behavioral anomaly analysis, MITRE ATT&CK TTP mapping, and PowerQuery generation via purple_ai tool.
Conducts threat hunts on Clawdstrike events: timelines, filtered queries, pattern correlations, IOC checks, MITRE ATT&CK mapping, and incident reports.
Share bugs, ideas, or general feedback.
当用户要围绕 artifact 进行调查分析时,使用这个 skill。 artifact 是 ASP 中的三级数据,每个 artifact 都挂载在一个 alert 下,是最小的需要调查的数据单元。
list_artifacts。create_enrichment 加 attach_enrichment_to_target。asp-enrichment-zh skill。list_artifacts。asp-enrichment-zh skill。list_artifacts。首选回复结构:
| Artifact ID | Value | Type | Role | Owner | Reputation | Summary |
|---|
然后在需要时补一句简短解释。
artifact_id。