New to Claude Skills? Learn how to install them →

Siem skills

Free agent skills tagged siem, ready to install into any SKILL.md-compatible agent.

Performing Alert Triage with Elastic SIEM

mukul975

Streamline alert triage processes in Elastic Security.

Security & ComplianceintermediatePython27.6k repo

Detecting Lateral Movement in Network

mukul975

Identify lateral movement techniques in enterprise networks.

Security & ComplianceintermediatePython · Shell27.6k repo

Implementing Security Monitoring with Datadog

mukul975

Set up comprehensive security monitoring for cloud infrastructure.

Security & ComplianceintermediatePython · Shell27.6k repo

Implementing SIEM Use Cases

mukul975

Enhance SIEM detection with structured use case implementation.

Security & ComplianceintermediatePython · Shell27.6k repo

Building Detection Rules with Sigma

mukul975

Create portable detection rules for SIEM platforms.

Security & ComplianceintermediatePython · Shell27.6k repo

Detecting Lateral Movement with Splunk

mukul975

Hunt for adversary lateral movement using Splunk.

Security & ComplianceintermediatePython27.6k repo

SIEM Correlation Rules for APT

mukul975

Detect advanced persistent threats with multi-event correlation.

Security & ComplianceintermediatePython · Shell27.6k repo

SIEM Use Case Tuning

mukul975

Reduce alert fatigue in your SIEM environment.

Security & ComplianceintermediatePython27.6k repo

Log Forwarding with Fluentd

Configures Fluent Bit as an endpoint log forwarder and Fluentd as the central aggregator for centralized log collection, routing, filtering, and enrichment, covering input plugins for syslog/file-tailing/application logs and output routing to Elasticsearch, S3, and Splunk. Use when setting up centralized log aggregation across distributed infrastructure or generating Fluent Bit/Fluentd configuration files for a new log pipeline.

Hunting for Windows Persistence

Systematically hunts for adversary persistence mechanisms across Windows endpoints, covering registry Run/RunOnce keys, services, startup folders, scheduled tasks, and WMI event subscriptions. Use when performing a broad persistence sweep during incident response or building SIEM detections that cover the full range of Windows persistence techniques (MITRE T1547).

Hunting for Living-off-the-Land Binaries

Proactively hunts for adversary abuse of legitimate, signed system binaries (LOLBins) used to execute malicious payloads, download files, or proxy execution while evading application allowlisting and defense-evasion controls. Use when building LOLBins detection rules for EDR/SIEM or when threat hunting for defense-evasion activity involving trusted system binaries.

Correlating Security Events in QRadar

Correlates security events in IBM QRadar SIEM using AQL (Ariel Query Language), custom rules, building blocks, and offense management to detect multi-stage attacks across network, endpoint, and application log sources. Use when SOC analysts need to investigate QRadar offenses, build correlation rules, or tune detection logic for reducing false positives.

Building Detection Rules with Splunk SPL

Build effective detection rules using Splunk Search Processing Language (SPL) correlation searches to identify security threats in SOC environments.

Analyzing Security Logs with Splunk

Leverages Splunk Enterprise Security and SPL (Search Processing Language) to investigate security incidents through log correlation, timeline reconstruction, and anomaly detection. Covers Windows event logs, firewall logs, proxy logs, and authentication data analysis. Activates for requests involving Splunk investigation, SPL queries, SIEM log analysis, security event correlation, or log-based incident investigation.