Use when cross-referencing extracted IOCs against recent SIEM alerts and SOAR cases.
原文语言:英语
菜单
这个仓库中的 skills
SkillsMP 已收集 dandye/adk_runbooks 中的 63 个 Skill。打开任一 Skill 可查看来源和详情。
dandye/adk_runbooks已展示 23 / 63 个已收集 Skill。
Use when cross-referencing extracted IOCs against recent SIEM alerts and SOAR cases.
原文语言:英语
Use when adding case comments, tags, or status updates to document actions in SOAR.
原文语言:英语
Use when standardizing multi-source threat intelligence enrichment for indicators.
原文语言:英语
Use when searching SOAR for active or historical cases relevant to an alert or investigation.
原文语言:英语
Use when writing markdown investigation or incident reports to standard output files.
原文语言:英语
Use when pivoting on GTI campaign identifiers, threat actors, and related infrastructure.
原文语言:英语
Use when submitting and verifying rule tuning pull requests in detection-as-code repositories.
原文语言:英语
Use when authoring, testing, and managing detection rules using Git-based CI/CD workflows.
原文语言:英语
Use when validating detection rule performance, reducing false positives, and tuning logic.
原文语言:英语
Use when formulating hypotheses and executing deep-dive proactive threat hunting missions.
原文语言:英语
Use when hunting for credential dumping, LSASS access, and Kerberoasting behaviors.
原文语言:英语
Use when sweeping organizational logs and telemetry for specific indicators of compromise.
原文语言:英语
Use when reconstructing sequential chronological timelines and process execution trees.
原文语言:英语
Use when identifying redundant or duplicate SOAR cases and linking or closing them.
原文语言:英语
Use when correlating GTI collection indicators against local telemetry and event logs.
原文语言:英语
Use when clustering related security cases by common entities, campaigns, or alert types.
原文语言:英语
Use when executing advanced multi-factor case grouping and relationship clustering.
原文语言:英语
Use when investigating a Google Threat Intelligence (GTI) Collection ID for threat context.
原文语言:英语
Use when summarizing alert triage decisions, key indicators, and immediate actions taken.
原文语言:英语
Use when drafting detailed case closure reports, root cause analysis, and impact summaries.
原文语言:英语
Use when documenting detection coverage assessments, test results, and tuning outcomes.
原文语言:英语
Use when structuring, formatting, and refining professional cybersecurity incident reports.
原文语言:英语
Use when performing initial host-level triage and executing endpoint isolation procedures.
原文语言:英语