بنقرة واحدة
defensive-soc-skills
يحتوي defensive-soc-skills على 3 من skills المجمعة من arttapon1، مع تغطية مهنية على مستوى المستودع وصفحات skill داخل الموقع.
Skills في هذا المستودع
Analyze security logs and incident data to reconstruct an attack timeline, build an incident response plan following NIST SP 800-61 / SANS PICERL, and produce a detailed technical report plus a concise executive summary. Use when the user mentions 'IR report,' 'incident response report,' 'incident analysis,' 'log analysis for incident,' 'attack timeline,' 'root cause analysis,' 'executive summary of incident,' 'post-incident report,' 'IR plan,' 'containment plan,' or has raw logs / alerts and needs them turned into an investigation and report.
Analyze logs, IOCs, and attack behavior to design high-fidelity SIEM detection rules. Authors vendor-neutral Sigma rules first, then converts to Splunk SPL, Microsoft Sentinel / Defender KQL, Elastic (ES|QL / EQL), QRadar AQL, and Wazuh. Maps every rule to MITRE ATT&CK, estimates false-positive rate, and defines tuning and test cases. Use when the user mentions 'detection rule,' 'SIEM rule,' 'detection engineering,' 'Sigma rule,' 'SPL,' 'KQL,' 'EQL,' 'ES|QL,' 'QRadar,' 'Wazuh,' 'correlation rule,' 'use case development,' 'alert,' 'detect this attack,' 'MITRE mapping,' or has incident/log data and wants detections that would catch it.
Design and generate SOAR automation playbooks that enrich alerts with threat intelligence (VirusTotal, Group-IB, AbuseIPDB, OTX) and orchestrate automated response via device APIs — blocking IOCs on firewalls (Palo Alto, Fortinet, Check Point), WAFs (Cloudflare, AWS WAF, F5), IPS, DLP, and EDR. Produces vendor-neutral playbook definitions with decision logic, approval gates, rollback, and safety guardrails. Use when the user mentions 'SOAR,' 'playbook,' 'automation playbook,' 'automated response,' 'auto-block,' 'block IP on firewall,' 'API integration,' 'enrich IOC,' 'VirusTotal API,' 'Group-IB,' 'threat intel enrichment,' 'firewall API,' 'WAF API,' 'orchestration,' 'auto containment,' or wants to automate detection-to-response.