com um clique
defensive-soc-skills
defensive-soc-skills contém 3 skills coletadas de arttapon1, com cobertura ocupacional por repositório e páginas de detalhe dentro do site.
Skills neste repositório
Analyze security logs and incident data to reconstruct an attack timeline, build an incident response plan following NIST SP 800-61 / SANS PICERL, and produce a detailed technical report plus a concise executive summary. Use when the user mentions 'IR report,' 'incident response report,' 'incident analysis,' 'log analysis for incident,' 'attack timeline,' 'root cause analysis,' 'executive summary of incident,' 'post-incident report,' 'IR plan,' 'containment plan,' or has raw logs / alerts and needs them turned into an investigation and report.
Analyze logs, IOCs, and attack behavior to design high-fidelity SIEM detection rules. Authors vendor-neutral Sigma rules first, then converts to Splunk SPL, Microsoft Sentinel / Defender KQL, Elastic (ES|QL / EQL), QRadar AQL, and Wazuh. Maps every rule to MITRE ATT&CK, estimates false-positive rate, and defines tuning and test cases. Use when the user mentions 'detection rule,' 'SIEM rule,' 'detection engineering,' 'Sigma rule,' 'SPL,' 'KQL,' 'EQL,' 'ES|QL,' 'QRadar,' 'Wazuh,' 'correlation rule,' 'use case development,' 'alert,' 'detect this attack,' 'MITRE mapping,' or has incident/log data and wants detections that would catch it.
Design and generate SOAR automation playbooks that enrich alerts with threat intelligence (VirusTotal, Group-IB, AbuseIPDB, OTX) and orchestrate automated response via device APIs — blocking IOCs on firewalls (Palo Alto, Fortinet, Check Point), WAFs (Cloudflare, AWS WAF, F5), IPS, DLP, and EDR. Produces vendor-neutral playbook definitions with decision logic, approval gates, rollback, and safety guardrails. Use when the user mentions 'SOAR,' 'playbook,' 'automation playbook,' 'automated response,' 'auto-block,' 'block IP on firewall,' 'API integration,' 'enrich IOC,' 'VirusTotal API,' 'Group-IB,' 'threat intel enrichment,' 'firewall API,' 'WAF API,' 'orchestration,' 'auto containment,' or wants to automate detection-to-response.