Use when evaluating threat detection opportunities (TDOs), generating synthetic UDM events, evaluating Chronicle rule coverage, and drafting YARA-L 2.0 rules.
Quellsprache: Englisch
Menü
SkillsMP hat 63 Skills aus dandye/adk_runbooks gesammelt. Öffne einen Skill, um Quelle und Details zu prüfen.
Es werden 40 von 63 gesammelten Skills angezeigt.
Use when evaluating threat detection opportunities (TDOs), generating synthetic UDM events, evaluating Chronicle rule coverage, and drafting YARA-L 2.0 rules.
Quellsprache: Englisch
Use when hunting for advanced persistent threat (APT) actor activity, tools, and infrastructure.
Quellsprache: Englisch
Use when hunting for lateral movement via PsExec, WMI, remote scheduled tasks, or WinRM.
Quellsprache: Englisch
Use when initiating threat hunting operations driven by GTI threat campaign intelligence.
Quellsprache: Englisch
Use when conducting initial reputation and threat intelligence lookups on suspicious observables.
Quellsprache: Englisch
Use when performing exhaustive forensic and intelligence analysis on complex indicators of compromise.
Quellsprache: Englisch
Use when enriching and verifying case artifacts with external threat intelligence platforms.
Quellsprache: Englisch
Use when executing network, host, or credential containment actions for validated malicious IOCs.
Quellsprache: Englisch
Use when scoring case urgency, prioritizing the queue, and running core investigations.
Quellsprache: Englisch
Use when executing containment, eradication, and recovery for confirmed compromised user credentials.
Quellsprache: Englisch
Use when coordinating response and remediation for advanced malware infections.
Quellsprache: Englisch
Use when responding to reported phishing emails, malicious links, or credential harvesting campaigns.
Quellsprache: Englisch
Use when responding to active ransomware deployment, host encryption, or extortion threats.
Quellsprache: Englisch
Use when compiling comprehensive incident investigation findings and executive summaries.
Quellsprache: Englisch
Use when triaging cloud security posture vulnerabilities and contextualizing finding risk.
Quellsprache: Englisch
Use when analyzing malware detection alerts, isolating infected endpoints, and scoping file executions.
Quellsprache: Englisch
Use when triaging anomalous or suspicious user authentication events, impossible travel, and credential anomalies.
Quellsprache: Englisch
Use when evaluating and categorizing incoming security alerts to determine severity and initial response actions.
Quellsprache: Englisch
Use when fetching GTI threat reputation and WHOIS intelligence for a specific domain name.
Quellsprache: Englisch
Use when retrieving Chronicle SecOps threat intelligence and IOC matches for a domain.
Quellsprache: Englisch
Use when looking up domain entity graph associations and historical context in Chronicle.
Quellsprache: Englisch
Use when searching UDM DNS query and resolution logs for a domain in Chronicle.
Quellsprache: Englisch
Use when querying Chronicle for network connections, HTTP requests, or TLS traffic to a domain.
Quellsprache: Englisch
Use when querying GTI and VirusTotal reputation and sandbox verdicts for a file hash.
Quellsprache: Englisch
Use when retrieving SecOps threat intelligence matches for a SHA256, SHA1, or MD5 hash.
Quellsprache: Englisch
Use when inspecting Chronicle entity records for known malicious or suspicious file hashes.
Quellsprache: Englisch
Use when searching Chronicle for process execution events matching a file hash.
Quellsprache: Englisch
Use when fetching GTI reputation, ASN, and geolocation details for an IP address.
Quellsprache: Englisch
Use when querying Chronicle SecOps threat intelligence feeds for an IP address.
Quellsprache: Englisch
Use when examining Chronicle entity graph and asset context for an internal or external IP.
Quellsprache: Englisch
Use when querying UDM network connection events in Chronicle involving a target IP address.
Quellsprache: Englisch
Use when retrieving GTI threat classification and URL category intelligence.
Quellsprache: Englisch
Use when querying SecOps threat intelligence indicators for a specific URL.
Quellsprache: Englisch
Use when searching Chronicle proxy and web access logs for HTTP/HTTPS requests to a URL.
Quellsprache: Englisch
Use when querying Chronicle user entity details, department, manager, and role context.
Quellsprache: Englisch
Use when searching Chronicle authentication events for a user's recent login activity.
Quellsprache: Englisch
Use when searching Chronicle endpoint logs for process launches initiated by a specific user.
Quellsprache: Englisch
Use when checking SOAR cases for overlapping entities to detect duplicate incidents.
Quellsprache: Englisch
Use when setting SOAR alert or case closure status and root cause reason codes.
Quellsprache: Englisch
Use when requesting human operator confirmation before disruptive remediation actions.
Quellsprache: Englisch