Siem skills
Free agent skills tagged siem, ready to install into any SKILL.md-compatible agent.
14 skills
Performing Alert Triage with Elastic SIEM
mukul975
Streamline alert triage processes in Elastic Security.
Detecting Lateral Movement in Network
mukul975
Identify lateral movement techniques in enterprise networks.
Implementing Security Monitoring with Datadog
mukul975
Set up comprehensive security monitoring for cloud infrastructure.
Implementing SIEM Use Cases
mukul975
Enhance SIEM detection with structured use case implementation.
Building Detection Rules with Sigma
mukul975
Create portable detection rules for SIEM platforms.
Detecting Lateral Movement with Splunk
mukul975
Hunt for adversary lateral movement using Splunk.
SIEM Correlation Rules for APT
mukul975
Detect advanced persistent threats with multi-event correlation.
SIEM Use Case Tuning
mukul975
Reduce alert fatigue in your SIEM environment.
Log Forwarding with Fluentd
Configures Fluent Bit as an endpoint log forwarder and Fluentd as the central aggregator for centralized log collection, routing, filtering, and enrichment, covering input plugins for syslog/file-tailing/application logs and output routing to Elasticsearch, S3, and Splunk. Use when setting up centralized log aggregation across distributed infrastructure or generating Fluent Bit/Fluentd configuration files for a new log pipeline.
Hunting for Windows Persistence
Systematically hunts for adversary persistence mechanisms across Windows endpoints, covering registry Run/RunOnce keys, services, startup folders, scheduled tasks, and WMI event subscriptions. Use when performing a broad persistence sweep during incident response or building SIEM detections that cover the full range of Windows persistence techniques (MITRE T1547).
Hunting for Living-off-the-Land Binaries
Proactively hunts for adversary abuse of legitimate, signed system binaries (LOLBins) used to execute malicious payloads, download files, or proxy execution while evading application allowlisting and defense-evasion controls. Use when building LOLBins detection rules for EDR/SIEM or when threat hunting for defense-evasion activity involving trusted system binaries.
Correlating Security Events in QRadar
Correlates security events in IBM QRadar SIEM using AQL (Ariel Query Language), custom rules, building blocks, and offense management to detect multi-stage attacks across network, endpoint, and application log sources. Use when SOC analysts need to investigate QRadar offenses, build correlation rules, or tune detection logic for reducing false positives.
Building Detection Rules with Splunk SPL
Build effective detection rules using Splunk Search Processing Language (SPL) correlation searches to identify security threats in SOC environments.
Analyzing Security Logs with Splunk
Leverages Splunk Enterprise Security and SPL (Search Processing Language) to investigate security incidents through log correlation, timeline reconstruction, and anomaly detection. Covers Windows event logs, firewall logs, proxy logs, and authentication data analysis. Activates for requests involving Splunk investigation, SPL queries, SIEM log analysis, security event correlation, or log-based incident investigation.
