Use when evaluating threat detection opportunities (TDOs), generating synthetic UDM events, evaluating Chronicle rule coverage, and drafting YARA-L 2.0 rules.
원문 언어: 영어
메뉴
SkillsMP는 dandye/adk_runbooks에서 63개의 skill을 수집했습니다. skill을 열어 소스와 세부 정보를 확인하세요.
수집된 skill 63개 중 40개를 표시합니다.
Use when evaluating threat detection opportunities (TDOs), generating synthetic UDM events, evaluating Chronicle rule coverage, and drafting YARA-L 2.0 rules.
원문 언어: 영어
Use when hunting for advanced persistent threat (APT) actor activity, tools, and infrastructure.
원문 언어: 영어
Use when hunting for lateral movement via PsExec, WMI, remote scheduled tasks, or WinRM.
원문 언어: 영어
Use when initiating threat hunting operations driven by GTI threat campaign intelligence.
원문 언어: 영어
Use when conducting initial reputation and threat intelligence lookups on suspicious observables.
원문 언어: 영어
Use when performing exhaustive forensic and intelligence analysis on complex indicators of compromise.
원문 언어: 영어
Use when enriching and verifying case artifacts with external threat intelligence platforms.
원문 언어: 영어
Use when executing network, host, or credential containment actions for validated malicious IOCs.
원문 언어: 영어
Use when scoring case urgency, prioritizing the queue, and running core investigations.
원문 언어: 영어
Use when executing containment, eradication, and recovery for confirmed compromised user credentials.
원문 언어: 영어
Use when coordinating response and remediation for advanced malware infections.
원문 언어: 영어
Use when responding to reported phishing emails, malicious links, or credential harvesting campaigns.
원문 언어: 영어
Use when responding to active ransomware deployment, host encryption, or extortion threats.
원문 언어: 영어
Use when compiling comprehensive incident investigation findings and executive summaries.
원문 언어: 영어
Use when triaging cloud security posture vulnerabilities and contextualizing finding risk.
원문 언어: 영어
Use when analyzing malware detection alerts, isolating infected endpoints, and scoping file executions.
원문 언어: 영어
Use when triaging anomalous or suspicious user authentication events, impossible travel, and credential anomalies.
원문 언어: 영어
Use when evaluating and categorizing incoming security alerts to determine severity and initial response actions.
원문 언어: 영어
Use when fetching GTI threat reputation and WHOIS intelligence for a specific domain name.
원문 언어: 영어
Use when retrieving Chronicle SecOps threat intelligence and IOC matches for a domain.
원문 언어: 영어
Use when looking up domain entity graph associations and historical context in Chronicle.
원문 언어: 영어
Use when searching UDM DNS query and resolution logs for a domain in Chronicle.
원문 언어: 영어
Use when querying Chronicle for network connections, HTTP requests, or TLS traffic to a domain.
원문 언어: 영어
Use when querying GTI and VirusTotal reputation and sandbox verdicts for a file hash.
원문 언어: 영어
Use when retrieving SecOps threat intelligence matches for a SHA256, SHA1, or MD5 hash.
원문 언어: 영어
Use when inspecting Chronicle entity records for known malicious or suspicious file hashes.
원문 언어: 영어
Use when searching Chronicle for process execution events matching a file hash.
원문 언어: 영어
Use when fetching GTI reputation, ASN, and geolocation details for an IP address.
원문 언어: 영어
Use when querying Chronicle SecOps threat intelligence feeds for an IP address.
원문 언어: 영어
Use when examining Chronicle entity graph and asset context for an internal or external IP.
원문 언어: 영어
Use when querying UDM network connection events in Chronicle involving a target IP address.
원문 언어: 영어
Use when retrieving GTI threat classification and URL category intelligence.
원문 언어: 영어
Use when querying SecOps threat intelligence indicators for a specific URL.
원문 언어: 영어
Use when searching Chronicle proxy and web access logs for HTTP/HTTPS requests to a URL.
원문 언어: 영어
Use when querying Chronicle user entity details, department, manager, and role context.
원문 언어: 영어
Use when searching Chronicle authentication events for a user's recent login activity.
원문 언어: 영어
Use when searching Chronicle endpoint logs for process launches initiated by a specific user.
원문 언어: 영어
Use when checking SOAR cases for overlapping entities to detect duplicate incidents.
원문 언어: 영어
Use when setting SOAR alert or case closure status and root cause reason codes.
원문 언어: 영어
Use when requesting human operator confirmation before disruptive remediation actions.
원문 언어: 영어