Interpret THOR scan results and explain what findings mean. Use when the user pastes THOR log lines, shares a log file, or asks how to triage Notices/Warnings/Alerts.
Goal: turn raw THOR output into an investigation plan.
THOR performs live forensic analysis and highlights suspicious elements using signatures. The analyst's job is to evaluate these findings using additional data sources and context.
In contrast to firewall logs, a high number of a particular THOR finding decreases its relevance:
Two recommended approaches (often combined):
Example workflow:
If user provides a log file path, run scripts/summarize_thor_log.py to extract a compact summary.
For each finding, ask:
If YES to most → Likely FP, document and filter. If NO to most → Treat as suspicious, investigate further.
npx skills add NextronSystems/thor-log-analysis下载完整 Skill 目录,包含 SKILL.md 及所有相关文件
Edit PDFs with natural-language instructions using the nano-pdf CLI.
Control Sonos speakers (discover/status/play/volume/group).
Terminal Spotify playback/search via spogo (preferred) or spotify_player.
Capture frames or clips from RTSP/ONVIF cameras.
CLI to manage emails via IMAP/SMTP. Use `himalaya` to list, read, write, reply, forward, search, and organize emails from the terminal. Supports multiple accounts and message composition with MML (MIME Meta Language).
Monitor blogs and RSS/Atom feeds for updates using the blogwatcher CLI.
Category:tools