siem▌
24 indexed skills · max 10 per page
detecting-insider-threat-with-ueba
mukul975/Anthropic-Cybersecurity-Skills · detecting-insider-threat-with-ueba
Implement User and Entity Behavior Analytics using Elasticsearch/OpenSearch to build behavioral baselines, calculate anomaly scores, perform peer group analysis, and detect insider threat indicators such as data exfiltration, privilege abuse, and unauthorized access patterns.
implementing-siem-use-case-tuning
mukul975/Anthropic-Cybersecurity-Skills · implementing-siem-use-case-tuning
Tune SIEM detection rules to reduce false positives by analyzing alert volumes, creating whitelists, adjusting thresholds, and measuring detection efficacy metrics in Splunk and Elastic
triaging-security-alerts-in-splunk
mukul975/Anthropic-Cybersecurity-Skills · triaging-security-alerts-in-splunk
Triages security alerts in Splunk Enterprise Security by classifying severity, investigating notable events, correlating related telemetry, and making escalation or closure decisions using SPL queries and the Incident Review dashboard. Use when SOC analysts face queued alerts from correlation searches, need to prioritize investigation order, or must document triage decisions for handoff to Tier 2/3 analysts.
implementing-siem-use-cases-for-detection
mukul975/Anthropic-Cybersecurity-Skills · implementing-siem-use-cases-for-detection
Implements SIEM detection use cases by designing correlation rules, threshold alerts, and behavioral analytics mapped to MITRE ATT&CK techniques across Splunk, Elastic, and Sentinel. Use when SOC teams need to expand detection coverage, formalize use case lifecycle management, or build a detection library aligned to organizational threat profile.
hunting-for-persistence-mechanisms-in-windows
mukul975/Anthropic-Cybersecurity-Skills · hunting-for-persistence-mechanisms-in-windows
Systematically hunt for adversary persistence mechanisms across Windows endpoints including registry, services, startup folders, and WMI subscriptions.
implementing-log-forwarding-with-fluentd
mukul975/Anthropic-Cybersecurity-Skills · implementing-log-forwarding-with-fluentd
Configure Fluentd and Fluent Bit for centralized log aggregation, routing, filtering, and enrichment across distributed infrastructure
detecting-aws-guardduty-findings-automation
mukul975/Anthropic-Cybersecurity-Skills · detecting-aws-guardduty-findings-automation
Automate AWS GuardDuty threat detection findings processing using EventBridge and Lambda to enable real-time incident response, automatic quarantine of compromised resources, and security notification workflows.
performing-log-source-onboarding-in-siem
mukul975/Anthropic-Cybersecurity-Skills · performing-log-source-onboarding-in-siem
Perform structured log source onboarding into SIEM platforms by configuring collectors, parsers, normalization, and validation for complete security visibility.
hunting-for-living-off-the-land-binaries
mukul975/Anthropic-Cybersecurity-Skills · hunting-for-living-off-the-land-binaries
Proactively hunt for adversary abuse of legitimate system binaries (LOLBins) to execute malicious payloads while evading detection.
detecting-lateral-movement-with-splunk
mukul975/Anthropic-Cybersecurity-Skills · detecting-lateral-movement-with-splunk
Detect adversary lateral movement across networks using Splunk SPL queries against Windows authentication logs, SMB traffic, and remote service abuse.