Stats
Actions
Tags
From security-compliance
Forensic walk of ThreatLocker audit logs to investigate a specific file, computer, or time window -- surfaces blocked executions, lateral movement, and pivot points. Use when user asks "investigate this file/host", "what happened on X", or during IR.
How this skill is triggered — by the user, by Claude, or both
Slash command
/security-compliance:audit-forensicsThe summary Claude sees in its skill listing — used to decide when to auto-load this skill
Inputs: one of file hash, file path, computer name, time window.
Inputs: one of file hash, file path, computer name, time window.
threatlocker_audit_search filtered to the input + time window.threatlocker_audit_file_history (cross-org occurrence).threatlocker_computers_get_checkins, threatlocker_audit_search action_type=blocked for the same host.ctx_execute:
npx claudepluginhub w159/tech-tools --plugin security-complianceProvides CDSS development patterns for drug interaction checking, dose validation, clinical scoring (NEWS2, qSOFA), and alert classification integrated into EMR workflows.