tag

siem

24 indexed skills · max 10 per page

skills (24)

performing-alert-triage-with-elastic-siem

mukul975/Anthropic-Cybersecurity-Skills · performing-alert-triage-with-elastic-siem

0

Perform systematic alert triage in Elastic Security SIEM to rapidly classify, prioritize, and investigate security alerts for SOC operations.

performing-threat-hunting-with-elastic-siem

mukul975/Anthropic-Cybersecurity-Skills · performing-threat-hunting-with-elastic-siem

0

Performs proactive threat hunting in Elastic Security SIEM using KQL/EQL queries, detection rules, and Timeline investigation to identify threats that evade automated detection. Use when SOC teams need to hunt for specific ATT&CK techniques, investigate anomalous behaviors, or validate detection coverage gaps using Elasticsearch and Kibana Security.

implementing-siem-correlation-rules-for-apt

mukul975/Anthropic-Cybersecurity-Skills · implementing-siem-correlation-rules-for-apt

0

Write multi-event correlation rules that detect APT lateral movement by chaining Windows authentication events, process execution telemetry, and network connection logs across hosts. Uses Splunk SPL and Sigma rule format to correlate Event IDs 4624, 4648, 4688, and Sysmon Events 1/3 within sliding time windows to surface attack sequences invisible to single-event detections.

detecting-lateral-movement-in-network

mukul975/Anthropic-Cybersecurity-Skills · detecting-lateral-movement-in-network

0

Identifies lateral movement techniques in enterprise networks by analyzing authentication logs, network flows, SMB traffic, and RDP sessions using Zeek, Velociraptor, and SIEM correlation rules to detect attackers moving between systems.

performing-false-positive-reduction-in-siem

mukul975/Anthropic-Cybersecurity-Skills · performing-false-positive-reduction-in-siem

0

Perform systematic SIEM false positive reduction through rule tuning, threshold adjustment, correlation refinement, and threat intelligence enrichment to combat alert fatigue.

implementing-security-monitoring-with-datadog

mukul975/Anthropic-Cybersecurity-Skills · implementing-security-monitoring-with-datadog

0

Implements security monitoring using Datadog Cloud SIEM, Cloud Security Management (CSM), and Workload Protection to detect threats, enforce compliance, and respond to security events across cloud and hybrid infrastructure. Covers Agent deployment, log source ingestion, detection rule creation, security dashboards, and automated notification workflows. Activates for requests involving Datadog security setup, Cloud SIEM configuration, CSM threat detection, or security monitoring dashboards.

detecting-rdp-brute-force-attacks

mukul975/Anthropic-Cybersecurity-Skills · detecting-rdp-brute-force-attacks

0

Detect RDP brute force attacks by analyzing Windows Security Event Logs for failed authentication patterns (Event ID 4625), successful logons after failures (Event ID 4624), NLA failures, and source IP frequency analysis.

building-detection-rule-with-splunk-spl

mukul975/Anthropic-Cybersecurity-Skills · building-detection-rule-with-splunk-spl

0

Build effective detection rules using Splunk Search Processing Language (SPL) correlation searches to identify security threats in SOC environments.

implementing-alert-fatigue-reduction

mukul975/Anthropic-Cybersecurity-Skills · implementing-alert-fatigue-reduction

0

Implements strategies to reduce SOC alert fatigue by tuning detection rules, consolidating duplicate alerts, implementing risk-based alerting, and measuring alert quality metrics to maintain analyst effectiveness and prevent critical alert dismissal. Use when SOC teams face overwhelming alert volumes, high false positive rates, or declining analyst performance.

detecting-insider-threat-with-ueba

mukul975/Anthropic-Cybersecurity-Skills · detecting-insider-threat-with-ueba

0

Implement User and Entity Behavior Analytics using Elasticsearch/OpenSearch to build behavioral baselines, calculate anomaly scores, perform peer group analysis, and detect insider threat indicators such as data exfiltration, privilege abuse, and unauthorized access patterns.

prevpage 1 / 3next