tag

siem

24 indexed skills · max 10 per page

skills (24)

implementing-siem-use-case-tuning

mukul975/Anthropic-Cybersecurity-Skills · implementing-siem-use-case-tuning

0

Tune SIEM detection rules to reduce false positives by analyzing alert volumes, creating whitelists, adjusting thresholds, and measuring detection efficacy metrics in Splunk and Elastic

triaging-security-alerts-in-splunk

mukul975/Anthropic-Cybersecurity-Skills · triaging-security-alerts-in-splunk

0

Triages security alerts in Splunk Enterprise Security by classifying severity, investigating notable events, correlating related telemetry, and making escalation or closure decisions using SPL queries and the Incident Review dashboard. Use when SOC analysts face queued alerts from correlation searches, need to prioritize investigation order, or must document triage decisions for handoff to Tier 2/3 analysts.

implementing-siem-use-cases-for-detection

mukul975/Anthropic-Cybersecurity-Skills · implementing-siem-use-cases-for-detection

0

Implements SIEM detection use cases by designing correlation rules, threshold alerts, and behavioral analytics mapped to MITRE ATT&CK techniques across Splunk, Elastic, and Sentinel. Use when SOC teams need to expand detection coverage, formalize use case lifecycle management, or build a detection library aligned to organizational threat profile.

hunting-for-persistence-mechanisms-in-windows

mukul975/Anthropic-Cybersecurity-Skills · hunting-for-persistence-mechanisms-in-windows

0

Systematically hunt for adversary persistence mechanisms across Windows endpoints including registry, services, startup folders, and WMI subscriptions.

correlating-security-events-in-qradar

mukul975/Anthropic-Cybersecurity-Skills · correlating-security-events-in-qradar

0

Correlates security events in IBM QRadar SIEM using AQL (Ariel Query Language), custom rules, building blocks, and offense management to detect multi-stage attacks across network, endpoint, and application log sources. Use when SOC analysts need to investigate QRadar offenses, build correlation rules, or tune detection logic for reducing false positives.

implementing-log-forwarding-with-fluentd

mukul975/Anthropic-Cybersecurity-Skills · implementing-log-forwarding-with-fluentd

0

Configure Fluentd and Fluent Bit for centralized log aggregation, routing, filtering, and enrichment across distributed infrastructure

detecting-aws-guardduty-findings-automation

mukul975/Anthropic-Cybersecurity-Skills · detecting-aws-guardduty-findings-automation

0

Automate AWS GuardDuty threat detection findings processing using EventBridge and Lambda to enable real-time incident response, automatic quarantine of compromised resources, and security notification workflows.

performing-log-source-onboarding-in-siem

mukul975/Anthropic-Cybersecurity-Skills · performing-log-source-onboarding-in-siem

0

Perform structured log source onboarding into SIEM platforms by configuring collectors, parsers, normalization, and validation for complete security visibility.

hunting-for-living-off-the-land-binaries

mukul975/Anthropic-Cybersecurity-Skills · hunting-for-living-off-the-land-binaries

0

Proactively hunt for adversary abuse of legitimate system binaries (LOLBins) to execute malicious payloads while evading detection.

detecting-lateral-movement-with-splunk

mukul975/Anthropic-Cybersecurity-Skills · detecting-lateral-movement-with-splunk

0

Detect adversary lateral movement across networks using Splunk SPL queries against Windows authentication logs, SMB traffic, and remote service abuse.

prevpage 2 / 3next