Skip to main content

Skills في هذا المستودع

dandye/adk_runbooks - الصفحة ٢

جمع SkillsMP عدد ٦٣ من skills من dandye/adk_runbooks. افتح أي skill لمراجعة مصدره وتفاصيله.

dandye/adk_runbooks

عرض ٢٣ من أصل ٦٣ skills مجمعة.

المهنة
غير مصنف
الوصف

Use when cross-referencing extracted IOCs against recent SIEM alerts and SOAR cases.

لغة النص الأصلي: الإنجليزية

آخر تحديث
المهنة
غير مصنف
الوصف

Use when adding case comments, tags, or status updates to document actions in SOAR.

لغة النص الأصلي: الإنجليزية

آخر تحديث
المهنة
غير مصنف
الوصف

Use when standardizing multi-source threat intelligence enrichment for indicators.

لغة النص الأصلي: الإنجليزية

آخر تحديث
المهنة
غير مصنف
الوصف

Use when searching SOAR for active or historical cases relevant to an alert or investigation.

لغة النص الأصلي: الإنجليزية

آخر تحديث
المهنة
غير مصنف
الوصف

Use when writing markdown investigation or incident reports to standard output files.

لغة النص الأصلي: الإنجليزية

آخر تحديث
المهنة
غير مصنف
الوصف

Use when pivoting on GTI campaign identifiers, threat actors, and related infrastructure.

لغة النص الأصلي: الإنجليزية

آخر تحديث
المهنة
غير مصنف
الوصف

Use when submitting and verifying rule tuning pull requests in detection-as-code repositories.

لغة النص الأصلي: الإنجليزية

آخر تحديث
المهنة
غير مصنف
الوصف

Use when authoring, testing, and managing detection rules using Git-based CI/CD workflows.

لغة النص الأصلي: الإنجليزية

آخر تحديث
المهنة
غير مصنف
الوصف

Use when validating detection rule performance, reducing false positives, and tuning logic.

لغة النص الأصلي: الإنجليزية

آخر تحديث
المهنة
غير مصنف
الوصف

Use when formulating hypotheses and executing deep-dive proactive threat hunting missions.

لغة النص الأصلي: الإنجليزية

آخر تحديث
المهنة
غير مصنف
الوصف

Use when hunting for credential dumping, LSASS access, and Kerberoasting behaviors.

لغة النص الأصلي: الإنجليزية

آخر تحديث
المهنة
غير مصنف
الوصف

Use when sweeping organizational logs and telemetry for specific indicators of compromise.

لغة النص الأصلي: الإنجليزية

آخر تحديث
المهنة
غير مصنف
الوصف

Use when reconstructing sequential chronological timelines and process execution trees.

لغة النص الأصلي: الإنجليزية

آخر تحديث
المهنة
غير مصنف
الوصف

Use when identifying redundant or duplicate SOAR cases and linking or closing them.

لغة النص الأصلي: الإنجليزية

آخر تحديث
المهنة
غير مصنف
الوصف

Use when correlating GTI collection indicators against local telemetry and event logs.

لغة النص الأصلي: الإنجليزية

آخر تحديث
المهنة
غير مصنف
الوصف

Use when clustering related security cases by common entities, campaigns, or alert types.

لغة النص الأصلي: الإنجليزية

آخر تحديث
المهنة
غير مصنف
الوصف

Use when executing advanced multi-factor case grouping and relationship clustering.

لغة النص الأصلي: الإنجليزية

آخر تحديث
المهنة
غير مصنف
الوصف

Use when investigating a Google Threat Intelligence (GTI) Collection ID for threat context.

لغة النص الأصلي: الإنجليزية

آخر تحديث
المهنة
غير مصنف
الوصف

Use when summarizing alert triage decisions, key indicators, and immediate actions taken.

لغة النص الأصلي: الإنجليزية

آخر تحديث
المهنة
غير مصنف
الوصف

Use when drafting detailed case closure reports, root cause analysis, and impact summaries.

لغة النص الأصلي: الإنجليزية

آخر تحديث
المهنة
غير مصنف
الوصف

Use when documenting detection coverage assessments, test results, and tuning outcomes.

لغة النص الأصلي: الإنجليزية

آخر تحديث
المهنة
غير مصنف
الوصف

Use when structuring, formatting, and refining professional cybersecurity incident reports.

لغة النص الأصلي: الإنجليزية

آخر تحديث
المهنة
غير مصنف
الوصف

Use when performing initial host-level triage and executing endpoint isolation procedures.

لغة النص الأصلي: الإنجليزية

آخر تحديث
عرض ٢٣ من أصل ٦٣ skills مجمعة.