en un clic
defensive-soc-skills
defensive-soc-skills contient 3 skills collectées depuis arttapon1, avec une couverture métier par dépôt et des pages de détail sur le site.
Skills dans ce dépôt
Analyze security logs and incident data to reconstruct an attack timeline, build an incident response plan following NIST SP 800-61 / SANS PICERL, and produce a detailed technical report plus a concise executive summary. Use when the user mentions 'IR report,' 'incident response report,' 'incident analysis,' 'log analysis for incident,' 'attack timeline,' 'root cause analysis,' 'executive summary of incident,' 'post-incident report,' 'IR plan,' 'containment plan,' or has raw logs / alerts and needs them turned into an investigation and report.
Analyze logs, IOCs, and attack behavior to design high-fidelity SIEM detection rules. Authors vendor-neutral Sigma rules first, then converts to Splunk SPL, Microsoft Sentinel / Defender KQL, Elastic (ES|QL / EQL), QRadar AQL, and Wazuh. Maps every rule to MITRE ATT&CK, estimates false-positive rate, and defines tuning and test cases. Use when the user mentions 'detection rule,' 'SIEM rule,' 'detection engineering,' 'Sigma rule,' 'SPL,' 'KQL,' 'EQL,' 'ES|QL,' 'QRadar,' 'Wazuh,' 'correlation rule,' 'use case development,' 'alert,' 'detect this attack,' 'MITRE mapping,' or has incident/log data and wants detections that would catch it.
Design and generate SOAR automation playbooks that enrich alerts with threat intelligence (VirusTotal, Group-IB, AbuseIPDB, OTX) and orchestrate automated response via device APIs — blocking IOCs on firewalls (Palo Alto, Fortinet, Check Point), WAFs (Cloudflare, AWS WAF, F5), IPS, DLP, and EDR. Produces vendor-neutral playbook definitions with decision logic, approval gates, rollback, and safety guardrails. Use when the user mentions 'SOAR,' 'playbook,' 'automation playbook,' 'automated response,' 'auto-block,' 'block IP on firewall,' 'API integration,' 'enrich IOC,' 'VirusTotal API,' 'Group-IB,' 'threat intel enrichment,' 'firewall API,' 'WAF API,' 'orchestration,' 'auto containment,' or wants to automate detection-to-response.