Skip to main content

Skills in this repository

dandye/adk_runbooks - Page 2

SkillsMP has collected 63 skills from dandye/adk_runbooks. Open a skill to review its source and details.

dandye/adk_runbooks

Showing 23 of 63 collected skills.

occupation
unclassified
description

Use when cross-referencing extracted IOCs against recent SIEM alerts and SOAR cases.

updated
occupation
unclassified
description

Use when adding case comments, tags, or status updates to document actions in SOAR.

updated
occupation
unclassified
description

Use when standardizing multi-source threat intelligence enrichment for indicators.

updated
occupation
unclassified
description

Use when searching SOAR for active or historical cases relevant to an alert or investigation.

updated
occupation
unclassified
description

Use when writing markdown investigation or incident reports to standard output files.

updated
occupation
unclassified
description

Use when pivoting on GTI campaign identifiers, threat actors, and related infrastructure.

updated
occupation
unclassified
description

Use when submitting and verifying rule tuning pull requests in detection-as-code repositories.

updated
occupation
unclassified
description

Use when authoring, testing, and managing detection rules using Git-based CI/CD workflows.

updated
occupation
unclassified
description

Use when validating detection rule performance, reducing false positives, and tuning logic.

updated
occupation
unclassified
description

Use when formulating hypotheses and executing deep-dive proactive threat hunting missions.

updated
occupation
unclassified
description

Use when hunting for credential dumping, LSASS access, and Kerberoasting behaviors.

updated
occupation
unclassified
description

Use when sweeping organizational logs and telemetry for specific indicators of compromise.

updated
occupation
unclassified
description

Use when reconstructing sequential chronological timelines and process execution trees.

updated
occupation
unclassified
description

Use when identifying redundant or duplicate SOAR cases and linking or closing them.

updated
occupation
unclassified
description

Use when correlating GTI collection indicators against local telemetry and event logs.

updated
occupation
unclassified
description

Use when clustering related security cases by common entities, campaigns, or alert types.

updated
occupation
unclassified
description

Use when executing advanced multi-factor case grouping and relationship clustering.

updated
occupation
unclassified
description

Use when investigating a Google Threat Intelligence (GTI) Collection ID for threat context.

updated
occupation
unclassified
description

Use when summarizing alert triage decisions, key indicators, and immediate actions taken.

updated
occupation
unclassified
description

Use when drafting detailed case closure reports, root cause analysis, and impact summaries.

updated
occupation
unclassified
description

Use when documenting detection coverage assessments, test results, and tuning outcomes.

updated
occupation
unclassified
description

Use when structuring, formatting, and refining professional cybersecurity incident reports.

updated
occupation
unclassified
description

Use when performing initial host-level triage and executing endpoint isolation procedures.

updated
Showing 23 of 63 collected skills.