siem▌
24 indexed skills · max 10 per page
implementing-endpoint-detection-with-wazuh
mukul975/Anthropic-Cybersecurity-Skills · implementing-endpoint-detection-with-wazuh
Deploy and configure Wazuh SIEM/XDR for endpoint detection including agent management, custom decoder and rule XML creation, alert querying via the Wazuh REST API, and automated response actions.
building-threat-intelligence-enrichment-in-splunk
mukul975/Anthropic-Cybersecurity-Skills · building-threat-intelligence-enrichment-in-splunk
Build automated threat intelligence enrichment pipelines in Splunk Enterprise Security using lookup tables, modular inputs, and the Threat Intelligence Framework.
building-detection-rules-with-sigma
mukul975/Anthropic-Cybersecurity-Skills · building-detection-rules-with-sigma
Builds vendor-agnostic detection rules using the Sigma rule format for threat detection across SIEM platforms including Splunk, Elastic, and Microsoft Sentinel. Use when creating portable detection logic from threat intelligence, mapping rules to MITRE ATT&CK techniques, or converting community Sigma rules into platform-specific queries using sigmac or pySigma backends.
performing-log-analysis-for-forensic-investigation
mukul975/Anthropic-Cybersecurity-Skills · performing-log-analysis-for-forensic-investigation
Collect, parse, and correlate system, application, and security logs to reconstruct events and establish timelines during forensic investigations.