Maps detection requirements to concrete data sources and field-level telemetry. Produces a prioritized data source list, field mapping table, visibility gap analysis, and logging configuration requirements. Use after a detection objective is defined to determine what logs and fields the detection logic will depend on.
Inputs:
Workflow steps:
Identify required data sources - List all log sources needed to observe the malicious behavior:
Prioritize data sources - Rank by:
Map to specific fields - For each critical data source, document exact fields needed:
Document visibility gaps - Identify missing telemetry:
Define data quality requirements - Specify:
Create data availability matrix - Table format:
| Data Source | Priority | Required Fields | Availability | Gaps/Requirements |
Outputs: Structured telemetry mapping document containing:
References:
Search for places (restaurants, cafes, etc.) via Google Places API proxy on localhost.
Interact with GitHub using the `gh` CLI. Use `gh issue`, `gh pr`, `gh run`, and `gh api` for issues, PRs, CI runs, and advanced queries.
Create or update AgentSkills. Use when designing, structuring, or packaging skills with scripts, references, and assets.
Start voice calls via the OpenClaw voice-call plugin.
Notion API for creating and managing pages, databases, and blocks.
Gemini CLI for one-shot Q&A, summaries, and generation.
Category:developer