Skip to main content

aws-samples/sample-sentinel-harness

SkillsMP는 aws-samples/sample-sentinel-harness에서 9개의 skill을 수집했습니다. skill을 열어 소스와 세부 정보를 확인하세요.

최근 기록된 소스 활동
SkillsMP 카탈로그 업데이트
수집된 skills
9
GitHub 스타
3
GitHub 포크
1

이 저장소의 skills

직업 카테고리 1개 · 100% 분류됨

수집된 skill 9개 중 9개를 표시합니다.

직업 분류
정보 보안 분석가
설명

Standard operating procedure for writing a Sigma or YARA detection rule and self-checking it before it goes to adversarial review. Use when authoring a new detection for a technique, log source, or malware family. Covers hypothesis framing, choosing Sigma vs…

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

General true-positive / false-positive alert triage rubric for a SOC analyst. Use when any SIEM alert needs a disposition and the analyst must corroborate the signal across siem_query, asset_lookup, and enrich_ioc, assign a severity, decide…

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Standard operating procedure for correlating a single CVE to the specific assets it affects and computing the blast radius across the estate. Use when a CVE lands and the question is not just "how bad is it" but "which of MY hosts are actually affected, how…

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Standard operating procedure for opening and annotating a security incident ticket at the end of a triage flow. Use when a triaged finding needs to be recorded as a ticket so a human can own containment and remediation. Covers the create_ticket field…

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Standard operating procedure for triaging security/operations findings across a multi-account estate. Use when posture or ops findings arrive from several accounts and an analyst must query them with ops_query, decide which findings are noise versus which…

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Standard operating procedure for triaging a single suspicious IP address in a SOC. Use when an IP arrives from an alert, firewall log, or threat feed and an analyst must decide whether it is malicious, whether it touched any asset in the estate, and whether…

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Standard operating procedure for reasoning about attack paths from exposed assets using the MITRE ATT&CK framework. Use when analyzing how an adversary could move from an internet-facing or exposed asset toward crown-jewel targets, to enumerate plausible…

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Standard operating procedure for triaging the impact of a CVE for a security operations team. Use when assessing a CVE's severity, exploitability, and asset impact, and deciding whether to patch, mitigate, monitor, or take no action. Combines CVSS, EPSS, and…

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Standard operating procedure for vetting an indicator of compromise (file hash, domain, or IP address) before acting on it. Use when an IOC arrives from an alert, threat feed, or report and needs a reputation lookup, a confidence rating, and false-positive…

원문 언어: 영어

업데이트
수집된 skill 9개 중 9개를 표시합니다.