Secops Detection Engineering
google/skills
Author, validate, test, and deploy YARA-L 2.0 detection rules and evaluate end-to-end detection coverage gaps in Google SecOps.
A skill your agent uses when asked to analyze, investigate, or report on honeypot server security.
$ npx skills add SCStelz/security-investigator --skill honeypot-investigation -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install SCStelz/security-investigator honeypot-investigation --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/SCStelz/security-investigator.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.github/skills/honeypot-investigation .claude/skills/honeypot-investigation && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "honeypot-investigation" agent skill from https://github.com/SCStelz/security-investigator/tree/main/.github/skills/honeypot-investigation into .claude/skills/honeypot-investigation/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "honeypot-investigation", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/SCStelz/security-investigator/tree/main/.github/skills/honeypot-investigationType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add SCStelz/security-investigator --skill honeypot-investigation -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install SCStelz/security-investigator honeypot-investigation --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/SCStelz/security-investigator.git skills-src && mkdir -p .agents/skills && cp -r skills-src/.github/skills/honeypot-investigation .agents/skills/honeypot-investigation && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "honeypot-investigation" agent skill from https://github.com/SCStelz/security-investigator/tree/main/.github/skills/honeypot-investigation into .agents/skills/honeypot-investigation/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "honeypot-investigation", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add SCStelz/security-investigator --skill honeypot-investigation -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install SCStelz/security-investigator honeypot-investigation --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/SCStelz/security-investigator.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/.github/skills/honeypot-investigation .cursor/skills/honeypot-investigation && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "honeypot-investigation" agent skill from https://github.com/SCStelz/security-investigator/tree/main/.github/skills/honeypot-investigation into .cursor/skills/honeypot-investigation/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "honeypot-investigation", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/SCStelz/security-investigator.git --path .github/skills/honeypot-investigation--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add SCStelz/security-investigator --skill honeypot-investigation -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install SCStelz/security-investigator honeypot-investigation --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/SCStelz/security-investigator.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/.github/skills/honeypot-investigation .gemini/skills/honeypot-investigation && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "honeypot-investigation" agent skill from https://github.com/SCStelz/security-investigator/tree/main/.github/skills/honeypot-investigation into .gemini/skills/honeypot-investigation/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "honeypot-investigation", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install SCStelz/security-investigator honeypot-investigationInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add SCStelz/security-investigator --skill honeypot-investigation -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/SCStelz/security-investigator.git skills-src && mkdir -p .github/skills && cp -r skills-src/.github/skills/honeypot-investigation .github/skills/honeypot-investigation && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "honeypot-investigation" agent skill from https://github.com/SCStelz/security-investigator/tree/main/.github/skills/honeypot-investigation into .github/skills/honeypot-investigation/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "honeypot-investigation", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add SCStelz/security-investigator --skill honeypot-investigation -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install SCStelz/security-investigator honeypot-investigation --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/SCStelz/security-investigator.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/.github/skills/honeypot-investigation .opencode/skills/honeypot-investigation && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "honeypot-investigation" agent skill from https://github.com/SCStelz/security-investigator/tree/main/.github/skills/honeypot-investigation into .opencode/skills/honeypot-investigation/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "honeypot-investigation", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
honeypot-investigationA skill your agent uses when asked to analyze, investigate, or report on honeypot server security.
Honeypot Investigation is an agent skill from SCStelz/security-investigator. Use this skill when asked to analyze, investigate, or report on honeypot server security. Triggers on keywords like "honeypot investigation", "analyze honeypot", "honeypot security", "honeypot report", or when a server name is mentioned with honeypot analysis context. This skill provides comprehensive security analysis including attack patterns, threat intelligence correlation, IP enrichment, vulnerability assessment, and executive report generation.
Its SKILL.md is about 5.8k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.
It sits in Security, covering OSINT, Report writing and Vulnerability scanning. The repository describes itself as: Automated security investigation tool using Microsoft MCP Servers, GitHub Copilot, Python Modules and custom copilot-instructions. The licence is MIT.
5 steps, taken from the step headings in SKILL.md.
Read from SKILL.md and the folder at commit 51e1385. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Shell commands in SKILL.md call:
pythonFrom the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md.
From URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Honeypot Investigation loads about 5.8k tokens when it runs. Until then it costs about 119 tokens; SKILL.md has 1,391 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from SCStelz/security-investigator at commit 51e1385, republished under its MIT licence (© SCStelz). 1,391 words, ~5,768 tokens.
.claude/skills/honeypot-investigation/SKILL.md (or your agent's skills folder).This agent performs comprehensive security analysis on honeypot servers to assess attack patterns, threat intelligence, vulnerabilities, and defensive effectiveness. Honeypots are decoy systems designed to attract attackers and provide early warning of emerging threats.
Before starting ANY honeypot investigation:
create_file for reports (NEVER use PowerShell terminal commands)Date Range Rules (from main copilot-instructions):
datetime(2025-12-10) to datetime(2025-12-14)| Parameter | Description | Example |
|---|---|---|
| Honeypot Name | Server/device name | honeypot-server |
| Time Range | Investigation period | last 48 hours, last 7 days |
reports/honeypot/Honeypot_Report_<hostname>_<timestamp>.mdtemp/honeypot_ips_<timestamp>.json, temp/honeypot_data_<timestamp>.jsonYOU MUST TRACK AND REPORT TIME AFTER EVERY MAJOR STEP:
[MM:SS] ✓ Step description (XX seconds)Required Reporting Points:
Execute ALL THREE queries in parallel using mcp_sentinel-data_query_lake:
let start = datetime(<StartDate>);
let end = datetime(<EndDate>);
let honeypot = '<HONEYPOT_NAME>';
SecurityEvent
| where TimeGenerated between (start .. end)
| where Computer contains honeypot // Use 'contains' for flexible hostname matching
| where EventID in (4625, 4771, 4776) // Failed logon attempts
| where isnotempty(IpAddress) and IpAddress != "-" // IpAddress is built-in field
| where IpAddress != "127.0.0.1" // Exclude localhost (internal honeypot traffic)
| summarize
FailedAttempts=count(),
FirstSeen=min(TimeGenerated),
LastSeen=max(TimeGenerated),
TargetAccounts=make_set(Account, 10)
by IpAddress, EventID
| extend EventType = case(
EventID == 4625, "Failed Logon",
EventID == 4771, "Kerberos Pre-Auth Failed",
EventID == 4776, "NTLM Auth Failed",
"Unknown")
| order by FailedAttempts desc
| take 50let start = datetime(<StartDate>);
let end = datetime(<EndDate>);
let honeypot = '<HONEYPOT_NAME>';
W3CIISLog
| where TimeGenerated between (start .. end)
| where Computer =~ honeypot
| where tolong(scStatus) >= 400 // HTTP errors (4xx/5xx) - scStatus is string type
| where cIP != "127.0.0.1" and cIP != "::1" // Exclude localhost (internal honeypot traffic)
| summarize
RequestCount=count(),
FirstSeen=min(TimeGenerated),
LastSeen=max(TimeGenerated),
TargetedURIs=make_set(csUriStem, 10),
StatusCodes=make_set(tolong(scStatus), 5) // Convert to long for proper aggregation
by IpAddress = cIP
| order by RequestCount desc
| take 50let start = datetime(<StartDate>);
let end = datetime(<EndDate>);
let honeypot = '<HONEYPOT_NAME>';
DeviceNetworkEvents
| where TimeGenerated between (start .. end)
| where DeviceName =~ honeypot
| where ActionType in ("ConnectionSuccess", "InboundConnectionAccepted", "ConnectionFound") // Successful inbound TCP connections
| where LocalPort in (3389, 80, 443, 445, 22, 21, 23, 8080, 8443) // Filter by attacked services (LocalPort = honeypot's listening port)
| where RemoteIP != "127.0.0.1" and RemoteIP != "::1" and RemoteIP != "::ffff:127.0.0.1" // Exclude localhost
| where RemoteIP !startswith "192.168." and RemoteIP !startswith "10." and RemoteIP !startswith "172.16." // Exclude RFC1918 private IPs
| where RemoteIP !startswith "fe80:" and RemoteIP !startswith "fc00:" and RemoteIP !startswith "fd00:" // Exclude IPv6 link-local and ULA
| where RemoteIP !startswith "::ffff:" // Filter out IPv6-mapped IPv4 addresses (reduces duplicate noise)
| summarize
ConnectionCount=count(),
FirstSeen=min(TimeGenerated),
LastSeen=max(TimeGenerated),
TargetedPorts=make_set(LocalPort, 10), // LocalPort = attacked services on honeypot
Actions=make_set(ActionType, 5)
by RemoteIP // RemoteIP = attacker source
| order by ConnectionCount desc
| take 50IMPORTANT: This query shows TCP connection establishment (network layer), NOT successful authentication. Attackers who appear here may still fail at the authentication layer (SecurityEvent 4625). For honeypots, all inbound connections should be treated as reconnaissance/attack attempts.
After Phase 1 completes:
temp/honeypot_ips_<timestamp>.json in format: {"ips": ["1.2.3.4", "5.6.7.8", ...]}[MM:SS] ✓ Failed connection queries completed (XX seconds) - [total_count] unique IPs identified, top [enrichment_count] prioritized for enrichmentExecute IP enrichment script AND Sentinel threat intel query in parallel:
# Read prioritized IPs from JSON file (top 10-15 by attack volume)
# This reduces token consumption by ~80% while maintaining critical intelligence
$env:PYTHONPATH = "<WORKSPACE_ROOT>"
cd "<WORKSPACE_ROOT>"
.\.venv\Scripts\python.exe enrich_ips.py --file temp/honeypot_ips_<timestamp>.jsonEnrichment provides (for prioritized IPs only):
is_vpn, is_proxy, is_tor)abuse_confidence_score, total_reports)eol-os, self-signed, c2), CPEs, hostnamesNote: Enrichment script provides aggregated statistics for all IPs - use these summary stats in report narrative instead of listing every IP
let target_ips = dynamic(["<IP1>", "<IP2>", "<IP3>", ...]); // From Phase 1 prioritized list (top 10-15 IPs)
ThreatIntelIndicators
| extend IndicatorType = replace_string(replace_string(replace_string(tostring(split(ObservableKey, ":", 0)), "[", ""), "]", ""), "\"", "")
| where IndicatorType in ("ipv4-addr", "ipv6-addr", "network-traffic")
| extend NetworkSourceIP = toupper(ObservableValue)
| where NetworkSourceIP in (target_ips)
| where IsActive and (ValidUntil > now() or isempty(ValidUntil))
| extend Description = tostring(parse_json(Data).description)
| where Description !contains_cs "State: inactive;" and Description !contains_cs "State: falsepos;"
| extend TrafficLightProtocolLevel = tostring(parse_json(AdditionalFields).TLPLevel)
| extend ActivityGroupNames = extract(@"ActivityGroup:(\S+)", 1, tostring(parse_json(Data).labels))
| summarize arg_max(TimeGenerated, *) by NetworkSourceIP
| project
TimeGenerated,
IPAddress = NetworkSourceIP,
ThreatDescription = Description,
ActivityGroupNames,
Confidence,
ValidUntil,
TrafficLightProtocolLevel,
IsActive
| order by Confidence desc, TimeGenerated descAfter Phase 2 completes:
temp/honeypot_data_<timestamp>.json[MM:SS] ✓ IP enrichment completed (XX seconds)Step 3A: Get Device ID from Sentinel
let honeypot = '<HONEYPOT_NAME>';
DeviceInfo
| where TimeGenerated > ago(30d)
| where DeviceName =~ honeypot or DeviceName contains honeypot
| summarize arg_max(TimeGenerated, *)
| project DeviceId, DeviceName, OSPlatform, OSVersion, PublicIPExtract DeviceId (GUID) from result - returns single most recent device record.
Step 3B: Query Security Incidents
let targetDevice = "<HONEYPOT_NAME>";
let targetDeviceId = "<DEVICE_ID>"; // REQUIRED: Get from DeviceInfo query (Step 3A)
let start = datetime(<StartDate>);
let end = datetime(<EndDate>);
let relevantAlerts = SecurityAlert
| where TimeGenerated between (start .. end)
| where Entities has targetDevice or Entities has targetDeviceId
| summarize arg_max(TimeGenerated, *) by SystemAlertId
| project SystemAlertId, AlertName, AlertSeverity, ProviderName, Tactics;
SecurityIncident
| where CreatedTime between (start .. end) // Filter on CreatedTime for incidents created in range
| summarize arg_max(TimeGenerated, *) by ProviderIncidentId // Get most recent state per ProviderIncidentId
| project ProviderIncidentId, Title, Severity, Status, Classification, CreatedTime, LastModifiedTime, Owner, AdditionalData, AlertIds, Labels
| where not(tostring(Labels) has "Redirected") // Exclude merged incidents
| mv-expand AlertId = AlertIds
| extend AlertId = tostring(AlertId)
| join kind=inner relevantAlerts on $left.AlertId == $right.SystemAlertId
| extend ProviderIncidentUrl = tostring(AdditionalData.providerIncidentUrl)
| extend OwnerUPN = tostring(Owner.userPrincipalName)
| extend LastModifiedTime = todatetime(LastModifiedTime)
| summarize
Title = any(Title),
Severity = any(Severity),
Status = any(Status),
Classification = any(Classification),
CreatedTime = any(CreatedTime),
LastModifiedTime = any(LastModifiedTime),
OwnerUPN = any(OwnerUPN),
ProviderIncidentUrl = any(ProviderIncidentUrl),
AlertCount = count(),
MitreTactics = make_set(Tactics)
by ProviderIncidentId
| order by LastModifiedTime desc
| take 10IMPORTANT:
This query joins SecurityIncident with SecurityAlert to provide full incident context
Deduplication: The final summarize statement collapses multiple alerts per incident into a single row (groups by ProviderIncidentId)
Filter on CreatedTime to find incidents created in the investigation period
Use arg_max(TimeGenerated, *) by IncidentNumber to get the most recent update for each incident (includes status changes, comments, etc.)
Returns up to 10 unique incidents (grouped by ProviderIncidentId to ensure one row per external incident ID)
⚠️ CHECK STATUS FIELD: Only report incidents with Status="New" or "Active" as threats. Status="Closed" + Classification="BenignPositive" = expected honeypot activity (do not flag as threat)
After Phase 3 completes:
[MM:SS] ✓ Security incidents query completed (XX seconds)⚠️ CRITICAL: TVM tables are snapshot tables — NO time filtering!
DeviceTvmSoftwareVulnerabilities has NO Timestamp or TimeGenerated columnwhere Timestamp between (...) — it will fail with a schema errorquery_lake) — TVM tables are only available via Advanced HuntingRunAdvancedHuntingQuery MCP tool onlylet deviceName = '<HONEYPOT_NAME>';
DeviceTvmSoftwareVulnerabilities
| where DeviceName startswith deviceName
| project
CveId,
VulnerabilitySeverityLevel,
SoftwareVendor,
SoftwareName,
SoftwareVersion,
RecommendedSecurityUpdate,
RecommendedSecurityUpdateId
| summarize by CveId, VulnerabilitySeverityLevel, SoftwareVendor, SoftwareName, SoftwareVersion, RecommendedSecurityUpdate, RecommendedSecurityUpdateId
| order by case(VulnerabilitySeverityLevel == "Critical", 1, VulnerabilitySeverityLevel == "High", 2, VulnerabilitySeverityLevel == "Medium", 3, 4) asc
| take 30Key columns returned:
CveId — CVE identifier (e.g., CVE-2025-15467)VulnerabilitySeverityLevel — String: Critical / High / Medium / LowSoftwareVendor, SoftwareName, SoftwareVersion — Affected software detailsRecommendedSecurityUpdate — Patch info (may be empty)🔴 PROHIBITED:
Timestamp or TimeGenerated filters (column does not exist)CvssScore (column does not exist — use VulnerabilitySeverityLevel instead)query_lake) for TVM tablesGetDefenderMachineVulnerabilities API (requires separate machine ID lookup, less reliable)After Phase 4 completes:
[MM:SS] ✓ Vulnerability scan completed (XX seconds)Use the Report Template (see section below) to create markdown report.
Critical Report Sections:
Report Generation:
create_file to save: reports/honeypot/Honeypot_Report_<hostname>_<timestamp>.mdAfter Phase 5 completes:
[MM:SS] ✓ Report generated (XX seconds)let start = datetime(<StartDate>);
let end = datetime(<EndDate>);
let honeypot = '<HONEYPOT_NAME>';
SecurityEvent
| where TimeGenerated between (start .. end)
| where Computer =~ honeypot
| where EventID == 4625 // Failed logon
| summarize FailedAttempts = count() by Account
| order by FailedAttempts desc
| take 20let start = datetime(<StartDate>);
let end = datetime(<EndDate>);
let honeypot = '<HONEYPOT_NAME>';
W3CIISLog
| where TimeGenerated between (start .. end)
| where Computer =~ honeypot
| where csUriStem has_any ("'", "union", "select", "script", "../", "..\\", "cmd.exe", "powershell")
| summarize
AttemptCount = count(),
FirstSeen = min(TimeGenerated),
LastSeen = max(TimeGenerated),
UniqueIPs = dcount(cIP)
by ExploitPattern = case(
csUriStem has_any ("'", "union", "select"), "SQL Injection",
csUriStem has "script", "XSS",
csUriStem has_any ("../", "..\\"), "Path Traversal",
csUriStem has_any ("cmd.exe", "powershell"), "Command Injection",
"Other")
| order by AttemptCount desclet start = datetime(<StartDate>);
let end = datetime(<EndDate>);
let honeypot = '<HONEYPOT_NAME>';
DeviceNetworkEvents
| where TimeGenerated between (start .. end)
| where DeviceName =~ honeypot
| summarize
DistinctPorts = dcount(RemotePort),
PortsScanned = make_set(RemotePort),
EventCount = count()
by RemoteIP
| where DistinctPorts >= 5 // Threshold: 5+ ports = scan
| order by DistinctPorts desc
| take 20let start = datetime(<StartDate>);
let end = datetime(<EndDate>);
let honeypot = '<HONEYPOT_NAME>';
let threshold = 50; // 50+ failed attempts = brute force
SecurityEvent
| where TimeGenerated between (start .. end)
| where Computer =~ honeypot
| where EventID == 4625
| extend IpAddress = extract(@"Source Network Address:\s+([^\s]+)", 1, tostring(EventData))
| summarize FailedAttempts = count() by IpAddress
| where FailedAttempts >= threshold
| order by FailedAttempts descUse this structure for executive reports:
# Honeypot Security Analysis - <HONEYPOT_NAME>
**Analysis Period:** <START_DATE> to <END_DATE> (<HOURS> hours)
**Report Generated:** <TIMESTAMP>
**Classification:** CONFIDENTIAL
---
## Executive Summary
[3 comprehensive paragraphs covering attack overview, threat landscape, and value delivered]
**Key Metrics:**
- **Total Attack Attempts:** [count]
- **Unique Attacking IPs:** [count]
- **Security Incidents Triggered:** [count]
- **Known Malicious IPs (Threat Intel):** [count] ([percentage]%)
- **Current Vulnerabilities:** [count] HIGH, [count] MEDIUM
---
## 1. Attack Surface Analysis
[Failed connections by source IP, geographic distribution, VPN/anonymization summary]
## 2. Threat Intelligence Correlation
[IPs matched in threat intel, highest confidence threats, MSTIC indicators]
## 3. Security Incidents
[Incidents involving honeypot with severity, status, classification, MITRE tactics]
## 4. Attack Pattern Analysis
[Targeted services, credential attacks, web exploitation, port scanning]
## 5. Honeypot Vulnerability Status
[CVE inventory, exploitation risk assessment, cross-reference with attacks]
## 6. Key Detection Insights
[MITRE ATT&CK mapping, novel indicators, threat actor attribution]
## 7. Honeypot Effectiveness
[Detection metrics, recommendations for optimization]
## 8. Conclusion
[Summary, key takeaways, immediate/short-term/long-term actions]
---
**Investigation Timeline:**
[Phase timing breakdown]
**Total Investigation Time:** [duration]| Issue | Solution |
|---|---|
| Missing honeypot in DeviceInfo table | Verify device name; check if device reports to Defender; try Computer field instead |
| No SecurityEvent logs | Device may not be sending Windows Security logs; verify log forwarding configuration |
| W3CIISLog table not found | IIS logging may not be enabled; query WebAccessLog or HTTP logs instead |
| IP enrichment script fails | Check ipinfo.io token in config.json; verify internet connectivity; check temp file exists |
| Date range returns no results | Verify date calculation (current date from context + proper offset); expand time range |
| KQL timeout | Reduce take limit; narrow time range; remove complex aggregations |
Before delivering report, verify:
reports/honeypot/Honeypot_Report_<hostname>_<timestamp>.mdThis skill follows all patterns from the main copilot-instructions.md:
create_file for all outputenrich_ips.py utilityExample invocations:
After completing the investigation, offer to visualize the attack data using the dedicated visualization skills:
Use the heatmap-visualization skill (.github/skills/heatmap-visualization/SKILL.md) to show attack patterns over time with threat intel drill-down.
When to offer:
Use the geomap-visualization skill (.github/skills/geomap-visualization/SKILL.md) to show attack origins on a world map.
When to offer:
Note: W3CIISLog includes native RemoteIPLatitude and RemoteIPLongitude fields - use these directly for geomap visualization without additional enrichment.
Last Updated: January 29, 2026
© SCStelz, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
Just SKILL.md in .github/skills/honeypot-investigation of SCStelz/security-investigator.
Open the folder on GitHubat commit 51e1385
Honeypot Investigation next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Honeypot Investigation this skillSCStelz/security-investigator | 249 | — | ~5.8k | Automated safety check: Pass | MIT | |
| Secops Detection Engineeringgoogle/skills | 21k | 1 repos | ~4.8k | Automated safety check: Pass | Apache-2.0 | |
| Recon Osinthypnguyen1209/offensive-claude | 388 | — | ~2.2k | Automated safety check: Pass | MIT | |
| Generating Threat Intelligence Reportsmukul975/Anthropic-Cybersecurity-Skills | 34k | — | ~1.9k | Automated safety check: Pass | Apache-2.0 | |
| Vulnerability Lookupptn1411/skill | 219 | — | ~1.1k | Automated safety check: Pass | None | |
| Security Auditoreigent-ai/eigent | 15k | — | ~1.8k | Automated safety check: Notes | Apache-2.0 |
google/skills
Author, validate, test, and deploy YARA-L 2.0 detection rules and evaluate end-to-end detection coverage gaps in Google SecOps.
hypnguyen1209/offensive-claude
A skill your agent uses when mapping a target's external attack surface or gathering OSINT — subdomain enumeration, attack-surface mapping (httpx/katana/JS secrets), subdomain takeover…
mukul975/Anthropic-Cybersecurity-Skills
Generates structured cyber threat intelligence reports at strategic, operational, and tactical levels tailored to specific audiences including executives, security operations teams, and technical…
ptn1411/skill
Multi-source threat intelligence and vulnerability lookup. An agent skill from ptn1411/skill.
eigent-ai/eigent
Audits source code, dependencies and config files for vulnerabilities and hardcoded secrets, using two bundled Python scanners and an OWASP Top 10 checklist.
NVIDIA/SkillSpector
Decides whether an agent skill is safe to install by combining a SkillSpector static scan with the agent's own source review, ending in APPROVE, CAUTION or REJECT.
SCStelz/security-investigator
A skill your agent uses when asked to investigate Conditional Access policy changes, sign-in failures related to CA policies (error codes 53000, 50074, 530032), or suspected policy…
SCStelz/security-investigator
Weekly review of an investigation tenant-context memory file against the most recent SOC scan reports (e.g.
SCStelz/security-investigator
A skill your agent uses when asked to create heatmaps, visualize patterns over time, show activity grids, or display aggregated data in a matrix format.
SCStelz/security-investigator
Report/investigate RUNTIME ACTIVITY of AI agents (Agent 365 / Copilot Studio / M365 Copilot / Work IQ) — agents used, tools/connectors, channels, tokens, prompt/reply content, and Prompt Shield…
SCStelz/security-investigator
Audit or report on AI agent security posture across Copilot Studio, Microsoft 365 Copilot, Microsoft Foundry, and third-party agents.
SCStelz/security-investigator
Audit Entra ID app registration and service principal security posture.
Categories
A skill your agent uses when asked to analyze, investigate, or report on honeypot server security. Honeypot Investigation is an agent skill from SCStelz/security-investigator. Use this skill when asked to analyze, investigate, or report on honeypot server security.
Honeypot Investigation fits situations like: asked to analyze; report on honeypot server security; keywords like honeypot investigation; analyze honeypot.
Run `npx skills add SCStelz/security-investigator --skill honeypot-investigation -a claude-code`. Or copy the skill folder (.github/skills/honeypot-investigation in SCStelz/security-investigator) into .claude/skills/honeypot-investigation in your project. Claude Code loads it when a task matches its description.
Run `npx skills add SCStelz/security-investigator --skill honeypot-investigation -a codex`. Or copy the skill folder (.github/skills/honeypot-investigation in SCStelz/security-investigator) into .agents/skills/honeypot-investigation in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add SCStelz/security-investigator --skill honeypot-investigation -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/honeypot-investigation, .gemini/skills/honeypot-investigation, .github/skills/honeypot-investigation and .opencode/skills/honeypot-investigation in your project.
Going by SKILL.md and its folder, Honeypot Investigation needs the command-line tools its instructions call (python).
SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
Honeypot Investigation is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 5.8k tokens (SKILL.md is roughly 23k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with Honeypot Investigation: Secops Detection Engineering (google/skills, 21k stars), Recon Osint (hypnguyen1209/offensive-claude, 388 stars), Generating Threat Intelligence Reports (mukul975/Anthropic-Cybersecurity-Skills, 34k stars) and Vulnerability Lookup (ptn1411/skill, 219 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
SCStelz (a GitHub user) maintains it in SCStelz/security-investigator, which has 249 GitHub stars. The repository holds 22 skills in this directory. The repository was last updated on October 8, 2026.
Source: SCStelz/security-investigator on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.