defense-log-analysis
Installation
SKILL.md
Log analysis & threat hunting
When it applies
You have logs (or a SIEM) and need to find attacker activity — during triage, IR, or proactive hunting. Pairs with each offensive skill: know the attack, hunt its footprint.
Why it works
Attacks leave patterns across log sources. Hunting hypothesis-first (pick a technique → query its signature → pivot on hits) beats scrolling. The same ATT&CK technique shows up in auth, web, cloud, and endpoint logs in characteristic ways.