tag

detection-engineering

12 indexed skills · max 10 per page

skills (12)

building-attack-pattern-library-from-cti-reports

mukul975/Anthropic-Cybersecurity-Skills · building-attack-pattern-library-from-cti-reports

0

Extract and catalog attack patterns from cyber threat intelligence reports into a structured STIX-based library mapped to MITRE ATT&CK for detection engineering and threat-informed defense.

detecting-fileless-attacks-on-endpoints

mukul975/Anthropic-Cybersecurity-Skills · detecting-fileless-attacks-on-endpoints

0

Detects fileless malware and in-memory attacks that execute entirely in RAM without writing persistent files to disk, evading traditional antivirus. Use when building detections for PowerShell-based attacks, reflective DLL injection, WMI persistence, and registry-resident malware. Activates for requests involving fileless malware detection, in-memory attacks, PowerShell exploitation, or living-off-the-land techniques.

performing-false-positive-reduction-in-siem

mukul975/Anthropic-Cybersecurity-Skills · performing-false-positive-reduction-in-siem

0

Perform systematic SIEM false positive reduction through rule tuning, threshold adjustment, correlation refinement, and threat intelligence enrichment to combat alert fatigue.

building-detection-rule-with-splunk-spl

mukul975/Anthropic-Cybersecurity-Skills · building-detection-rule-with-splunk-spl

0

Build effective detection rules using Splunk Search Processing Language (SPL) correlation searches to identify security threats in SOC environments.

implementing-alert-fatigue-reduction

mukul975/Anthropic-Cybersecurity-Skills · implementing-alert-fatigue-reduction

0

Implements strategies to reduce SOC alert fatigue by tuning detection rules, consolidating duplicate alerts, implementing risk-based alerting, and measuring alert quality metrics to maintain analyst effectiveness and prevent critical alert dismissal. Use when SOC teams face overwhelming alert volumes, high false positive rates, or declining analyst performance.

implementing-siem-use-case-tuning

mukul975/Anthropic-Cybersecurity-Skills · implementing-siem-use-case-tuning

0

Tune SIEM detection rules to reduce false positives by analyzing alert volumes, creating whitelists, adjusting thresholds, and measuring detection efficacy metrics in Splunk and Elastic

implementing-siem-use-cases-for-detection

mukul975/Anthropic-Cybersecurity-Skills · implementing-siem-use-cases-for-detection

0

Implements SIEM detection use cases by designing correlation rules, threshold alerts, and behavioral analytics mapped to MITRE ATT&CK techniques across Splunk, Elastic, and Sentinel. Use when SOC teams need to expand detection coverage, formalize use case lifecycle management, or build a detection library aligned to organizational threat profile.

detecting-evasion-techniques-in-endpoint-logs

mukul975/Anthropic-Cybersecurity-Skills · detecting-evasion-techniques-in-endpoint-logs

0

Detects defense evasion techniques used by adversaries in endpoint logs including log tampering, timestomping, process injection, and security tool disabling. Use when investigating suspicious endpoint behavior, building detection rules for evasion tactics, or conducting threat hunting for stealthy adversary activity. Activates for requests involving evasion detection, defense evasion analysis, log tampering detection, or MITRE ATT&CK TA0005.

performing-purple-team-atomic-testing

mukul975/Anthropic-Cybersecurity-Skills · performing-purple-team-atomic-testing

0

Executes Atomic Red Team tests mapped to MITRE ATT&CK techniques, performs coverage gap analysis across the ATT&CK matrix, and runs detection validation loops to measure blue team visibility. Covers Invoke-AtomicRedTeam PowerShell execution, ATT&CK Navigator layer generation for heatmaps, Sigma rule correlation, and continuous atomic testing pipelines. Activates for requests involving purple team exercises, atomic test execution, ATT&CK coverage assessment, detection engineering validation, or adversary emulation testing.

mapping-mitre-attack-techniques

mukul975/Anthropic-Cybersecurity-Skills · mapping-mitre-attack-techniques

0

Maps observed adversary behaviors, security alerts, and detection rules to MITRE ATT&CK techniques and sub-techniques to quantify detection coverage and guide control prioritization. Use when building an ATT&CK-based coverage heatmap, tagging SIEM alerts with technique IDs, aligning security controls to adversary playbooks, or reporting threat exposure to executives. Activates for requests involving ATT&CK Navigator, Sigma rules, MITRE D3FEND, or coverage gap analysis.

prevpage 1 / 2next