Use when cross-referencing extracted IOCs against recent SIEM alerts and SOAR cases.
Skills in this repository
dandye/adk_runbooks - Page 2
SkillsMP has collected 63 skills from dandye/adk_runbooks. Open a skill to review its source and details.
dandye/adk_runbooksShowing 23 of 63 collected skills.
Use when adding case comments, tags, or status updates to document actions in SOAR.
Use when standardizing multi-source threat intelligence enrichment for indicators.
Use when searching SOAR for active or historical cases relevant to an alert or investigation.
Use when writing markdown investigation or incident reports to standard output files.
Use when pivoting on GTI campaign identifiers, threat actors, and related infrastructure.
Use when submitting and verifying rule tuning pull requests in detection-as-code repositories.
Use when authoring, testing, and managing detection rules using Git-based CI/CD workflows.
Use when validating detection rule performance, reducing false positives, and tuning logic.
Use when formulating hypotheses and executing deep-dive proactive threat hunting missions.
Use when hunting for credential dumping, LSASS access, and Kerberoasting behaviors.
Use when sweeping organizational logs and telemetry for specific indicators of compromise.
Use when reconstructing sequential chronological timelines and process execution trees.
Use when identifying redundant or duplicate SOAR cases and linking or closing them.
Use when correlating GTI collection indicators against local telemetry and event logs.
Use when clustering related security cases by common entities, campaigns, or alert types.
Use when executing advanced multi-factor case grouping and relationship clustering.
Use when investigating a Google Threat Intelligence (GTI) Collection ID for threat context.
Use when summarizing alert triage decisions, key indicators, and immediate actions taken.
Use when drafting detailed case closure reports, root cause analysis, and impact summaries.
Use when documenting detection coverage assessments, test results, and tuning outcomes.
Use when structuring, formatting, and refining professional cybersecurity incident reports.
Use when performing initial host-level triage and executing endpoint isolation procedures.