tag

sentinel

4 indexed skills · max 10 per page

skills (4)

implementing-siem-use-cases-for-detection

mukul975/Anthropic-Cybersecurity-Skills · implementing-siem-use-cases-for-detection

0

Implements SIEM detection use cases by designing correlation rules, threshold alerts, and behavioral analytics mapped to MITRE ATT&CK techniques across Splunk, Elastic, and Sentinel. Use when SOC teams need to expand detection coverage, formalize use case lifecycle management, or build a detection library aligned to organizational threat profile.

detecting-azure-service-principal-abuse

mukul975/Anthropic-Cybersecurity-Skills · detecting-azure-service-principal-abuse

0

Detect and investigate Azure service principal abuse including privilege escalation, credential compromise, admin consent bypass, and unauthorized enumeration in Microsoft Entra ID environments.

detecting-azure-lateral-movement

mukul975/Anthropic-Cybersecurity-Skills · detecting-azure-lateral-movement

0

Detect lateral movement in Azure AD/Entra ID environments using Microsoft Graph API audit logs, Azure Sentinel KQL hunting queries, and sign-in anomaly correlation to identify privilege escalation, token theft, and cross-tenant pivoting.

building-detection-rules-with-sigma

mukul975/Anthropic-Cybersecurity-Skills · building-detection-rules-with-sigma

0

Builds vendor-agnostic detection rules using the Sigma rule format for threat detection across SIEM platforms including Splunk, Elastic, and Microsoft Sentinel. Use when creating portable detection logic from threat intelligence, mapping rules to MITRE ATT&CK techniques, or converting community Sigma rules into platform-specific queries using sigmac or pySigma backends.