timeline-creation

Create investigation timelines from security events, detections, or LCQL queries. Performs HOLISTIC investigations - not just process trees, but initial access hunting, org-wide scope assessment, lateral movement detection, and full host context. Builds Timeline Hive records documenting findings with events, detections, entities, and analyst notes. Use for incident investigation, threat hunting, alert triage, or building SOC working reports.

$ 安裝

git clone https://github.com/refractionPOINT/documentation /tmp/documentation && cp -r /tmp/documentation/marketplace/plugins/lc-essentials/skills/timeline-creation ~/.claude/skills/documentation

// tip: Run this command in your terminal to install the skill