Use when evaluating threat detection opportunities (TDOs), generating synthetic UDM events, evaluating Chronicle rule coverage, and drafting YARA-L 2.0 rules.
原文の言語: 英語
メニュー
SkillsMP は dandye/adk_runbooks から 63 件の skill を収集しています。skill を開くとソースと詳細を確認できます。
収集済み skill 63 件中 40 件を表示しています。
Use when evaluating threat detection opportunities (TDOs), generating synthetic UDM events, evaluating Chronicle rule coverage, and drafting YARA-L 2.0 rules.
原文の言語: 英語
Use when hunting for advanced persistent threat (APT) actor activity, tools, and infrastructure.
原文の言語: 英語
Use when hunting for lateral movement via PsExec, WMI, remote scheduled tasks, or WinRM.
原文の言語: 英語
Use when initiating threat hunting operations driven by GTI threat campaign intelligence.
原文の言語: 英語
Use when conducting initial reputation and threat intelligence lookups on suspicious observables.
原文の言語: 英語
Use when performing exhaustive forensic and intelligence analysis on complex indicators of compromise.
原文の言語: 英語
Use when enriching and verifying case artifacts with external threat intelligence platforms.
原文の言語: 英語
Use when executing network, host, or credential containment actions for validated malicious IOCs.
原文の言語: 英語
Use when scoring case urgency, prioritizing the queue, and running core investigations.
原文の言語: 英語
Use when executing containment, eradication, and recovery for confirmed compromised user credentials.
原文の言語: 英語
Use when coordinating response and remediation for advanced malware infections.
原文の言語: 英語
Use when responding to reported phishing emails, malicious links, or credential harvesting campaigns.
原文の言語: 英語
Use when responding to active ransomware deployment, host encryption, or extortion threats.
原文の言語: 英語
Use when compiling comprehensive incident investigation findings and executive summaries.
原文の言語: 英語
Use when triaging cloud security posture vulnerabilities and contextualizing finding risk.
原文の言語: 英語
Use when analyzing malware detection alerts, isolating infected endpoints, and scoping file executions.
原文の言語: 英語
Use when triaging anomalous or suspicious user authentication events, impossible travel, and credential anomalies.
原文の言語: 英語
Use when evaluating and categorizing incoming security alerts to determine severity and initial response actions.
原文の言語: 英語
Use when fetching GTI threat reputation and WHOIS intelligence for a specific domain name.
原文の言語: 英語
Use when retrieving Chronicle SecOps threat intelligence and IOC matches for a domain.
原文の言語: 英語
Use when looking up domain entity graph associations and historical context in Chronicle.
原文の言語: 英語
Use when searching UDM DNS query and resolution logs for a domain in Chronicle.
原文の言語: 英語
Use when querying Chronicle for network connections, HTTP requests, or TLS traffic to a domain.
原文の言語: 英語
Use when querying GTI and VirusTotal reputation and sandbox verdicts for a file hash.
原文の言語: 英語
Use when retrieving SecOps threat intelligence matches for a SHA256, SHA1, or MD5 hash.
原文の言語: 英語
Use when inspecting Chronicle entity records for known malicious or suspicious file hashes.
原文の言語: 英語
Use when searching Chronicle for process execution events matching a file hash.
原文の言語: 英語
Use when fetching GTI reputation, ASN, and geolocation details for an IP address.
原文の言語: 英語
Use when querying Chronicle SecOps threat intelligence feeds for an IP address.
原文の言語: 英語
Use when examining Chronicle entity graph and asset context for an internal or external IP.
原文の言語: 英語
Use when querying UDM network connection events in Chronicle involving a target IP address.
原文の言語: 英語
Use when retrieving GTI threat classification and URL category intelligence.
原文の言語: 英語
Use when querying SecOps threat intelligence indicators for a specific URL.
原文の言語: 英語
Use when searching Chronicle proxy and web access logs for HTTP/HTTPS requests to a URL.
原文の言語: 英語
Use when querying Chronicle user entity details, department, manager, and role context.
原文の言語: 英語
Use when searching Chronicle authentication events for a user's recent login activity.
原文の言語: 英語
Use when searching Chronicle endpoint logs for process launches initiated by a specific user.
原文の言語: 英語
Use when checking SOAR cases for overlapping entities to detect duplicate incidents.
原文の言語: 英語
Use when setting SOAR alert or case closure status and root cause reason codes.
原文の言語: 英語
Use when requesting human operator confirmation before disruptive remediation actions.
原文の言語: 英語