Skip to main content

dandye/adk_runbooks

SkillsMP는 dandye/adk_runbooks에서 63개의 skill을 수집했습니다. skill을 열어 소스와 세부 정보를 확인하세요.

최근 기록된 소스 활동
SkillsMP 카탈로그 업데이트
수집된 skills
63
GitHub 스타
82
GitHub 포크
14

이 저장소의 skills

분류 대기 중

수집된 skill 63개 중 40개를 표시합니다.

직업 분류
미분류
설명

Use when evaluating threat detection opportunities (TDOs), generating synthetic UDM events, evaluating Chronicle rule coverage, and drafting YARA-L 2.0 rules.

원문 언어: 영어

업데이트
직업 분류
미분류
설명

Use when hunting for advanced persistent threat (APT) actor activity, tools, and infrastructure.

원문 언어: 영어

업데이트
직업 분류
미분류
설명

Use when hunting for lateral movement via PsExec, WMI, remote scheduled tasks, or WinRM.

원문 언어: 영어

업데이트
직업 분류
미분류
설명

Use when initiating threat hunting operations driven by GTI threat campaign intelligence.

원문 언어: 영어

업데이트
직업 분류
미분류
설명

Use when conducting initial reputation and threat intelligence lookups on suspicious observables.

원문 언어: 영어

업데이트
직업 분류
미분류
설명

Use when performing exhaustive forensic and intelligence analysis on complex indicators of compromise.

원문 언어: 영어

업데이트
직업 분류
미분류
설명

Use when enriching and verifying case artifacts with external threat intelligence platforms.

원문 언어: 영어

업데이트
직업 분류
미분류
설명

Use when executing network, host, or credential containment actions for validated malicious IOCs.

원문 언어: 영어

업데이트
직업 분류
미분류
설명

Use when scoring case urgency, prioritizing the queue, and running core investigations.

원문 언어: 영어

업데이트
직업 분류
미분류
설명

Use when executing containment, eradication, and recovery for confirmed compromised user credentials.

원문 언어: 영어

업데이트
직업 분류
미분류
설명

Use when coordinating response and remediation for advanced malware infections.

원문 언어: 영어

업데이트
직업 분류
미분류
설명

Use when responding to reported phishing emails, malicious links, or credential harvesting campaigns.

원문 언어: 영어

업데이트
직업 분류
미분류
설명

Use when responding to active ransomware deployment, host encryption, or extortion threats.

원문 언어: 영어

업데이트
직업 분류
미분류
설명

Use when compiling comprehensive incident investigation findings and executive summaries.

원문 언어: 영어

업데이트
직업 분류
미분류
설명

Use when triaging cloud security posture vulnerabilities and contextualizing finding risk.

원문 언어: 영어

업데이트
직업 분류
미분류
설명

Use when analyzing malware detection alerts, isolating infected endpoints, and scoping file executions.

원문 언어: 영어

업데이트
직업 분류
미분류
설명

Use when triaging anomalous or suspicious user authentication events, impossible travel, and credential anomalies.

원문 언어: 영어

업데이트
직업 분류
미분류
설명

Use when evaluating and categorizing incoming security alerts to determine severity and initial response actions.

원문 언어: 영어

업데이트
직업 분류
미분류
설명

Use when fetching GTI threat reputation and WHOIS intelligence for a specific domain name.

원문 언어: 영어

업데이트
직업 분류
미분류
설명

Use when retrieving Chronicle SecOps threat intelligence and IOC matches for a domain.

원문 언어: 영어

업데이트
직업 분류
미분류
설명

Use when looking up domain entity graph associations and historical context in Chronicle.

원문 언어: 영어

업데이트
직업 분류
미분류
설명

Use when searching UDM DNS query and resolution logs for a domain in Chronicle.

원문 언어: 영어

업데이트
직업 분류
미분류
설명

Use when querying Chronicle for network connections, HTTP requests, or TLS traffic to a domain.

원문 언어: 영어

업데이트
직업 분류
미분류
설명

Use when querying GTI and VirusTotal reputation and sandbox verdicts for a file hash.

원문 언어: 영어

업데이트
직업 분류
미분류
설명

Use when retrieving SecOps threat intelligence matches for a SHA256, SHA1, or MD5 hash.

원문 언어: 영어

업데이트
직업 분류
미분류
설명

Use when inspecting Chronicle entity records for known malicious or suspicious file hashes.

원문 언어: 영어

업데이트
직업 분류
미분류
설명

Use when searching Chronicle for process execution events matching a file hash.

원문 언어: 영어

업데이트
직업 분류
미분류
설명

Use when fetching GTI reputation, ASN, and geolocation details for an IP address.

원문 언어: 영어

업데이트
직업 분류
미분류
설명

Use when querying Chronicle SecOps threat intelligence feeds for an IP address.

원문 언어: 영어

업데이트
직업 분류
미분류
설명

Use when examining Chronicle entity graph and asset context for an internal or external IP.

원문 언어: 영어

업데이트
직업 분류
미분류
설명

Use when querying UDM network connection events in Chronicle involving a target IP address.

원문 언어: 영어

업데이트
직업 분류
미분류
설명

Use when retrieving GTI threat classification and URL category intelligence.

원문 언어: 영어

업데이트
직업 분류
미분류
설명

Use when querying SecOps threat intelligence indicators for a specific URL.

원문 언어: 영어

업데이트
직업 분류
미분류
설명

Use when searching Chronicle proxy and web access logs for HTTP/HTTPS requests to a URL.

원문 언어: 영어

업데이트
직업 분류
미분류
설명

Use when querying Chronicle user entity details, department, manager, and role context.

원문 언어: 영어

업데이트
직업 분류
미분류
설명

Use when searching Chronicle authentication events for a user's recent login activity.

원문 언어: 영어

업데이트
직업 분류
미분류
설명

Use when searching Chronicle endpoint logs for process launches initiated by a specific user.

원문 언어: 영어

업데이트
직업 분류
미분류
설명

Use when checking SOAR cases for overlapping entities to detect duplicate incidents.

원문 언어: 영어

업데이트
직업 분류
미분류
설명

Use when setting SOAR alert or case closure status and root cause reason codes.

원문 언어: 영어

업데이트
직업 분류
미분류
설명

Use when requesting human operator confirmation before disruptive remediation actions.

원문 언어: 영어

업데이트
수집된 skill 63개 중 40개를 표시합니다.