tag

soc

34 indexed skills · max 10 per page

skills (34)

performing-alert-triage-with-elastic-siem

mukul975/Anthropic-Cybersecurity-Skills · performing-alert-triage-with-elastic-siem

0

Perform systematic alert triage in Elastic Security SIEM to rapidly classify, prioritize, and investigate security alerts for SOC operations.

building-automated-malware-submission-pipeline

mukul975/Anthropic-Cybersecurity-Skills · building-automated-malware-submission-pipeline

0

Builds an automated malware submission and analysis pipeline that collects suspicious files from endpoints and email gateways, submits them to sandbox environments and multi-engine scanners, and generates verdicts with IOCs for SIEM integration. Use when SOC teams need to scale malware analysis beyond manual sandbox submissions for high-volume alert triage.

performing-threat-hunting-with-elastic-siem

mukul975/Anthropic-Cybersecurity-Skills · performing-threat-hunting-with-elastic-siem

0

Performs proactive threat hunting in Elastic Security SIEM using KQL/EQL queries, detection rules, and Timeline investigation to identify threats that evade automated detection. Use when SOC teams need to hunt for specific ATT&CK techniques, investigate anomalous behaviors, or validate detection coverage gaps using Elasticsearch and Kibana Security.

performing-soc-tabletop-exercise

mukul975/Anthropic-Cybersecurity-Skills · performing-soc-tabletop-exercise

0

Performs tabletop exercises for SOC teams simulating security incidents through discussion-based scenarios to test incident response procedures, communication workflows, and decision-making under pressure without impacting production systems. Use when organizations need to validate IR playbooks, train analysts, or meet compliance requirements for incident response testing.

building-threat-intelligence-feed-integration

mukul975/Anthropic-Cybersecurity-Skills · building-threat-intelligence-feed-integration

0

Builds automated threat intelligence feed integration pipelines connecting STIX/TAXII feeds, open-source threat intel, and commercial TI platforms into SIEM and security tools for real-time IOC matching and alerting. Use when SOC teams need to operationalize threat intelligence by automating feed ingestion, normalization, scoring, and distribution to detection systems.

performing-false-positive-reduction-in-siem

mukul975/Anthropic-Cybersecurity-Skills · performing-false-positive-reduction-in-siem

0

Perform systematic SIEM false positive reduction through rule tuning, threshold adjustment, correlation refinement, and threat intelligence enrichment to combat alert fatigue.

building-detection-rule-with-splunk-spl

mukul975/Anthropic-Cybersecurity-Skills · building-detection-rule-with-splunk-spl

0

Build effective detection rules using Splunk Search Processing Language (SPL) correlation searches to identify security threats in SOC environments.

building-soc-escalation-matrix

mukul975/Anthropic-Cybersecurity-Skills · building-soc-escalation-matrix

0

Build a structured SOC escalation matrix defining severity tiers, response SLAs, escalation paths, and notification procedures for security incidents.

performing-user-behavior-analytics

mukul975/Anthropic-Cybersecurity-Skills · performing-user-behavior-analytics

0

Performs User and Entity Behavior Analytics (UEBA) to detect anomalous user activities including impossible travel, unusual access patterns, privilege abuse, and insider threats using SIEM-based behavioral baselines and statistical analysis. Use when SOC teams need to identify compromised accounts or insider threats through deviation from established behavioral norms.

performing-lateral-movement-detection

mukul975/Anthropic-Cybersecurity-Skills · performing-lateral-movement-detection

0

Detects lateral movement techniques including Pass-the-Hash, PsExec, WMI execution, RDP pivoting, and SMB-based spreading using SIEM correlation of Windows event logs, network flow data, and endpoint telemetry mapped to MITRE ATT&CK Lateral Movement (TA0008) techniques.

prevpage 1 / 4next