Skip to main content

dandye/adk_runbooks

SkillsMP 已收集 dandye/adk_runbooks 中的 63 个 Skill。打开任一 Skill 可查看来源和详情。

最近记录的来源活动
SkillsMP 收录数据更新
已收集 skills
63
GitHub 星标
82
GitHub Forks
14

这个仓库中的 skills

职业分类待补全

已展示 40 / 63 个已收集 Skill。

职业分类
未分类
描述

Use when evaluating threat detection opportunities (TDOs), generating synthetic UDM events, evaluating Chronicle rule coverage, and drafting YARA-L 2.0 rules.

原文语言:英语

更新
职业分类
未分类
描述

Use when hunting for advanced persistent threat (APT) actor activity, tools, and infrastructure.

原文语言:英语

更新
职业分类
未分类
描述

Use when hunting for lateral movement via PsExec, WMI, remote scheduled tasks, or WinRM.

原文语言:英语

更新
职业分类
未分类
描述

Use when initiating threat hunting operations driven by GTI threat campaign intelligence.

原文语言:英语

更新
职业分类
未分类
描述

Use when conducting initial reputation and threat intelligence lookups on suspicious observables.

原文语言:英语

更新
职业分类
未分类
描述

Use when performing exhaustive forensic and intelligence analysis on complex indicators of compromise.

原文语言:英语

更新
职业分类
未分类
描述

Use when enriching and verifying case artifacts with external threat intelligence platforms.

原文语言:英语

更新
职业分类
未分类
描述

Use when executing network, host, or credential containment actions for validated malicious IOCs.

原文语言:英语

更新
职业分类
未分类
描述

Use when scoring case urgency, prioritizing the queue, and running core investigations.

原文语言:英语

更新
职业分类
未分类
描述

Use when executing containment, eradication, and recovery for confirmed compromised user credentials.

原文语言:英语

更新
职业分类
未分类
描述

Use when coordinating response and remediation for advanced malware infections.

原文语言:英语

更新
职业分类
未分类
描述

Use when responding to reported phishing emails, malicious links, or credential harvesting campaigns.

原文语言:英语

更新
职业分类
未分类
描述

Use when responding to active ransomware deployment, host encryption, or extortion threats.

原文语言:英语

更新
职业分类
未分类
描述

Use when compiling comprehensive incident investigation findings and executive summaries.

原文语言:英语

更新
职业分类
未分类
描述

Use when triaging cloud security posture vulnerabilities and contextualizing finding risk.

原文语言:英语

更新
职业分类
未分类
描述

Use when analyzing malware detection alerts, isolating infected endpoints, and scoping file executions.

原文语言:英语

更新
职业分类
未分类
描述

Use when triaging anomalous or suspicious user authentication events, impossible travel, and credential anomalies.

原文语言:英语

更新
职业分类
未分类
描述

Use when evaluating and categorizing incoming security alerts to determine severity and initial response actions.

原文语言:英语

更新
职业分类
未分类
描述

Use when fetching GTI threat reputation and WHOIS intelligence for a specific domain name.

原文语言:英语

更新
职业分类
未分类
描述

Use when retrieving Chronicle SecOps threat intelligence and IOC matches for a domain.

原文语言:英语

更新
职业分类
未分类
描述

Use when looking up domain entity graph associations and historical context in Chronicle.

原文语言:英语

更新
职业分类
未分类
描述

Use when searching UDM DNS query and resolution logs for a domain in Chronicle.

原文语言:英语

更新
职业分类
未分类
描述

Use when querying Chronicle for network connections, HTTP requests, or TLS traffic to a domain.

原文语言:英语

更新
职业分类
未分类
描述

Use when querying GTI and VirusTotal reputation and sandbox verdicts for a file hash.

原文语言:英语

更新
职业分类
未分类
描述

Use when retrieving SecOps threat intelligence matches for a SHA256, SHA1, or MD5 hash.

原文语言:英语

更新
职业分类
未分类
描述

Use when inspecting Chronicle entity records for known malicious or suspicious file hashes.

原文语言:英语

更新
职业分类
未分类
描述

Use when fetching GTI reputation, ASN, and geolocation details for an IP address.

原文语言:英语

更新
职业分类
未分类
描述

Use when querying Chronicle SecOps threat intelligence feeds for an IP address.

原文语言:英语

更新
职业分类
未分类
描述

Use when examining Chronicle entity graph and asset context for an internal or external IP.

原文语言:英语

更新
职业分类
未分类
描述

Use when querying UDM network connection events in Chronicle involving a target IP address.

原文语言:英语

更新
职业分类
未分类
描述

Use when retrieving GTI threat classification and URL category intelligence.

原文语言:英语

更新
职业分类
未分类
描述

Use when querying SecOps threat intelligence indicators for a specific URL.

原文语言:英语

更新
职业分类
未分类
描述

Use when searching Chronicle proxy and web access logs for HTTP/HTTPS requests to a URL.

原文语言:英语

更新
职业分类
未分类
描述

Use when querying Chronicle user entity details, department, manager, and role context.

原文语言:英语

更新
职业分类
未分类
描述

Use when searching Chronicle authentication events for a user's recent login activity.

原文语言:英语

更新
职业分类
未分类
描述

Use when searching Chronicle endpoint logs for process launches initiated by a specific user.

原文语言:英语

更新
职业分类
未分类
描述

Use when checking SOAR cases for overlapping entities to detect duplicate incidents.

原文语言:英语

更新
职业分类
未分类
描述

Use when setting SOAR alert or case closure status and root cause reason codes.

原文语言:英语

更新
职业分类
未分类
描述

Use when requesting human operator confirmation before disruptive remediation actions.

原文语言:英语

更新
已展示 40 / 63 个已收集 Skill。