Use when evaluating threat detection opportunities (TDOs), generating synthetic UDM events, evaluating Chronicle rule coverage, and drafting YARA-L 2.0 rules.
原文语言:英语
菜单
SkillsMP 已收集 dandye/adk_runbooks 中的 63 个 Skill。打开任一 Skill 可查看来源和详情。
已展示 40 / 63 个已收集 Skill。
Use when evaluating threat detection opportunities (TDOs), generating synthetic UDM events, evaluating Chronicle rule coverage, and drafting YARA-L 2.0 rules.
原文语言:英语
Use when hunting for advanced persistent threat (APT) actor activity, tools, and infrastructure.
原文语言:英语
Use when hunting for lateral movement via PsExec, WMI, remote scheduled tasks, or WinRM.
原文语言:英语
Use when initiating threat hunting operations driven by GTI threat campaign intelligence.
原文语言:英语
Use when conducting initial reputation and threat intelligence lookups on suspicious observables.
原文语言:英语
Use when performing exhaustive forensic and intelligence analysis on complex indicators of compromise.
原文语言:英语
Use when enriching and verifying case artifacts with external threat intelligence platforms.
原文语言:英语
Use when executing network, host, or credential containment actions for validated malicious IOCs.
原文语言:英语
Use when scoring case urgency, prioritizing the queue, and running core investigations.
原文语言:英语
Use when executing containment, eradication, and recovery for confirmed compromised user credentials.
原文语言:英语
Use when coordinating response and remediation for advanced malware infections.
原文语言:英语
Use when responding to reported phishing emails, malicious links, or credential harvesting campaigns.
原文语言:英语
Use when responding to active ransomware deployment, host encryption, or extortion threats.
原文语言:英语
Use when compiling comprehensive incident investigation findings and executive summaries.
原文语言:英语
Use when triaging cloud security posture vulnerabilities and contextualizing finding risk.
原文语言:英语
Use when analyzing malware detection alerts, isolating infected endpoints, and scoping file executions.
原文语言:英语
Use when triaging anomalous or suspicious user authentication events, impossible travel, and credential anomalies.
原文语言:英语
Use when evaluating and categorizing incoming security alerts to determine severity and initial response actions.
原文语言:英语
Use when fetching GTI threat reputation and WHOIS intelligence for a specific domain name.
原文语言:英语
Use when retrieving Chronicle SecOps threat intelligence and IOC matches for a domain.
原文语言:英语
Use when looking up domain entity graph associations and historical context in Chronicle.
原文语言:英语
Use when searching UDM DNS query and resolution logs for a domain in Chronicle.
原文语言:英语
Use when querying Chronicle for network connections, HTTP requests, or TLS traffic to a domain.
原文语言:英语
Use when querying GTI and VirusTotal reputation and sandbox verdicts for a file hash.
原文语言:英语
Use when retrieving SecOps threat intelligence matches for a SHA256, SHA1, or MD5 hash.
原文语言:英语
Use when inspecting Chronicle entity records for known malicious or suspicious file hashes.
原文语言:英语
Use when searching Chronicle for process execution events matching a file hash.
原文语言:英语
Use when fetching GTI reputation, ASN, and geolocation details for an IP address.
原文语言:英语
Use when querying Chronicle SecOps threat intelligence feeds for an IP address.
原文语言:英语
Use when examining Chronicle entity graph and asset context for an internal or external IP.
原文语言:英语
Use when querying UDM network connection events in Chronicle involving a target IP address.
原文语言:英语
Use when retrieving GTI threat classification and URL category intelligence.
原文语言:英语
Use when querying SecOps threat intelligence indicators for a specific URL.
原文语言:英语
Use when searching Chronicle proxy and web access logs for HTTP/HTTPS requests to a URL.
原文语言:英语
Use when querying Chronicle user entity details, department, manager, and role context.
原文语言:英语
Use when searching Chronicle authentication events for a user's recent login activity.
原文语言:英语
Use when searching Chronicle endpoint logs for process launches initiated by a specific user.
原文语言:英语
Use when checking SOAR cases for overlapping entities to detect duplicate incidents.
原文语言:英语
Use when setting SOAR alert or case closure status and root cause reason codes.
原文语言:英语
Use when requesting human operator confirmation before disruptive remediation actions.
原文语言:英语