Analyze suspicious cloud identity and access events, including role changes, new keys, unusual regions, and privilege escalation. Recommend evidence-preserving response actions.
原文语言:英语
菜单
SkillsMP 已收集 Sec-Link/Argus-Agentic-SOC-Platform 中的 10 个 Skill。打开任一 Skill 可查看来源和详情。
已展示 10 / 10 个已收集 Skill。
Analyze suspicious cloud identity and access events, including role changes, new keys, unusual regions, and privilege escalation. Recommend evidence-preserving response actions.
原文语言:英语
Assess possible data movement using destinations, protocols, volume, files, and user context. Identify evidence gaps and recommend low-risk validation and containment actions.
原文语言:英语
Analyze suspicious DNS behavior such as high entropy, beaconing, rare domains, unusual record types, and query volume. Distinguish indicators from confirmed C2 and recommend safe validation.
原文语言:英语
Create a prioritized, reversible containment plan based only on observed evidence. Include owner, verification, rollback, and approval requirements; never perform destructive actions automatically.
原文语言:英语
Assess possible insider risk from unusual access, downloads, privilege use, and policy violations. Maintain neutral language, minimize personal data, and recommend auditable investigative steps.
原文语言:英语
Analyze process execution, downloaded files, hashes, parent-child chains, persistence, and host impact. Separate observed facts from hypotheses and propose safe collection and containment steps.
原文语言:英语
Analyze suspicious email indicators, sender authentication, URLs, attachments, user impact, and recommended containment. Never claim a link or attachment is malicious without evidence. Return concise findings and follow-up tasks.
原文语言:英语
Triage ransomware indicators such as mass file changes, encryption processes, ransom notes, and lateral movement. Prioritize isolation, evidence preservation, recovery coordination, and safe next tasks.
原文语言:英语
Investigate unusual authentication activity using source IP, account, time, geolocation, MFA, and privilege context. Recommend validation steps and avoid changing ticket status.
原文语言:英语
Prioritize vulnerabilities using asset criticality, exploitability, exposure, known exploitation, compensating controls, and business impact. Do not invent CVEs or affected versions.
原文语言:英语