root@eolas:~$ ./load_capabilities --all [OK] mounting vault 
// knowledge-base :: capabilities-overview

EOLAS//VAULT

A structured, portable knowledge base for threat intelligence, malware analysis, OSINT, detection engineering, and AI security research — methodology, reusable skills, automated workflows, and reference knowledge in one disciplined system.

● Active Portable master methodology Obsidian + CLI + MCP compatible Git-versioned, multi-host synced
20+
Reusable Skills
7
Behavioral Methods
12+
Detection Libraries
Multi
LLM Config Profiles
End-to-end
Automated Workflows

What the Vault Does

A methodology engine. The vault encodes how an analyst works: the tool chains, prompt templates, runbooks, model configurations, and hard-won reference knowledge that turn a one-off investigation into a repeatable, auditable process. Every artifact is machine-readable, navigable from the CLI, and consumable by LLM agents. The payoff is expertise that lives in a system — available to every analyst and agent who needs it, and steady whoever is at the keyboard.

Capability Domains

Reusable skills span the full analyst lifecycle — from a raw sample or a single name to a finished report, IOCs in a sharing platform, and tuned detections in production. Each one packages an entire discipline into a repeatable procedure, so a single analyst can take on work across domains and reach a defensible result the same way every time.

End-to-End Workflows

Multi-step runbooks chain skills into complete pipelines — for example, taking a dangerous-looking artifact safely from intake to shareable intelligence. They remove the seams between steps, so a whole investigation runs as one continuous, auditable flow with nothing dropped at the hand-offs.

📥Safe Intake
defang & quarantine
🔬Analyse
static / dynamic
📐Signatures
YARA / Sigma
🛰️Enrich
IOC pivoting
📤Share
MISP ingestion
📝Deliver
shareable intel

Reference Knowledge

Beyond skills, the vault carries curated reference material that analysts and agents draw on mid-investigation, kept as living summaries of concepts, patterns, and methodology. It puts hard-won context within reach at the moment of decision, so accuracy holds up under time pressure and never rides on memory alone.

A breadth of reference domains.

Summary-level knowledge spans malware behavior, threat-actor tradecraft, the evolving AI threat landscape, reverse-engineering fundamentals, detection reference material, agentic-SOC architecture, and defensive-AI patterns — plus an investigations index so prior work is never duplicated. Each is maintained as a digestible overview that points to deeper methodology when needed.

Malware Behavior Actor Tradecraft AI Threat Landscape RE Fundamentals Detection Reference Agentic-SOC Architecture Defensive-AI Patterns Investigations Index

Automation & Orchestration

The vault is wired for hands-off operation across machines and channels. Upkeep, sync, and routine collection run on their own, so the system stays current and consistent everywhere while analyst attention goes to the work that genuinely needs human judgement.

Why It Matters

One disciplined system, many capabilities.

The Eolas Vault turns scattered expertise into an operational asset: consistent methodology, reusable across machines and models, safe by construction, and continuously improving. Whether driven by a human analyst or an autonomous agent, the work is repeatable, auditable, and ready to scale.

Open Blueprint