Use when evaluating threat detection opportunities (TDOs), generating synthetic UDM events, evaluating Chronicle rule coverage, and drafting YARA-L 2.0 rules.
Idioma del texto original: inglés
Menú
SkillsMP ha recopilado 63 skills de dandye/adk_runbooks. Abre una skill para revisar su origen y sus detalles.
Mostrando 40 de 63 skills recopiladas.
Use when evaluating threat detection opportunities (TDOs), generating synthetic UDM events, evaluating Chronicle rule coverage, and drafting YARA-L 2.0 rules.
Idioma del texto original: inglés
Use when hunting for advanced persistent threat (APT) actor activity, tools, and infrastructure.
Idioma del texto original: inglés
Use when hunting for lateral movement via PsExec, WMI, remote scheduled tasks, or WinRM.
Idioma del texto original: inglés
Use when initiating threat hunting operations driven by GTI threat campaign intelligence.
Idioma del texto original: inglés
Use when conducting initial reputation and threat intelligence lookups on suspicious observables.
Idioma del texto original: inglés
Use when performing exhaustive forensic and intelligence analysis on complex indicators of compromise.
Idioma del texto original: inglés
Use when enriching and verifying case artifacts with external threat intelligence platforms.
Idioma del texto original: inglés
Use when executing network, host, or credential containment actions for validated malicious IOCs.
Idioma del texto original: inglés
Use when scoring case urgency, prioritizing the queue, and running core investigations.
Idioma del texto original: inglés
Use when executing containment, eradication, and recovery for confirmed compromised user credentials.
Idioma del texto original: inglés
Use when coordinating response and remediation for advanced malware infections.
Idioma del texto original: inglés
Use when responding to reported phishing emails, malicious links, or credential harvesting campaigns.
Idioma del texto original: inglés
Use when responding to active ransomware deployment, host encryption, or extortion threats.
Idioma del texto original: inglés
Use when compiling comprehensive incident investigation findings and executive summaries.
Idioma del texto original: inglés
Use when triaging cloud security posture vulnerabilities and contextualizing finding risk.
Idioma del texto original: inglés
Use when analyzing malware detection alerts, isolating infected endpoints, and scoping file executions.
Idioma del texto original: inglés
Use when triaging anomalous or suspicious user authentication events, impossible travel, and credential anomalies.
Idioma del texto original: inglés
Use when evaluating and categorizing incoming security alerts to determine severity and initial response actions.
Idioma del texto original: inglés
Use when fetching GTI threat reputation and WHOIS intelligence for a specific domain name.
Idioma del texto original: inglés
Use when retrieving Chronicle SecOps threat intelligence and IOC matches for a domain.
Idioma del texto original: inglés
Use when looking up domain entity graph associations and historical context in Chronicle.
Idioma del texto original: inglés
Use when searching UDM DNS query and resolution logs for a domain in Chronicle.
Idioma del texto original: inglés
Use when querying Chronicle for network connections, HTTP requests, or TLS traffic to a domain.
Idioma del texto original: inglés
Use when querying GTI and VirusTotal reputation and sandbox verdicts for a file hash.
Idioma del texto original: inglés
Use when retrieving SecOps threat intelligence matches for a SHA256, SHA1, or MD5 hash.
Idioma del texto original: inglés
Use when inspecting Chronicle entity records for known malicious or suspicious file hashes.
Idioma del texto original: inglés
Use when searching Chronicle for process execution events matching a file hash.
Idioma del texto original: inglés
Use when fetching GTI reputation, ASN, and geolocation details for an IP address.
Idioma del texto original: inglés
Use when querying Chronicle SecOps threat intelligence feeds for an IP address.
Idioma del texto original: inglés
Use when examining Chronicle entity graph and asset context for an internal or external IP.
Idioma del texto original: inglés
Use when querying UDM network connection events in Chronicle involving a target IP address.
Idioma del texto original: inglés
Use when retrieving GTI threat classification and URL category intelligence.
Idioma del texto original: inglés
Use when querying SecOps threat intelligence indicators for a specific URL.
Idioma del texto original: inglés
Use when searching Chronicle proxy and web access logs for HTTP/HTTPS requests to a URL.
Idioma del texto original: inglés
Use when querying Chronicle user entity details, department, manager, and role context.
Idioma del texto original: inglés
Use when searching Chronicle authentication events for a user's recent login activity.
Idioma del texto original: inglés
Use when searching Chronicle endpoint logs for process launches initiated by a specific user.
Idioma del texto original: inglés
Use when checking SOAR cases for overlapping entities to detect duplicate incidents.
Idioma del texto original: inglés
Use when setting SOAR alert or case closure status and root cause reason codes.
Idioma del texto original: inglés
Use when requesting human operator confirmation before disruptive remediation actions.
Idioma del texto original: inglés