New to Claude Skills? Learn how to install them →

Splunk skills

Free agent skills tagged splunk, ready to install into any SKILL.md-compatible agent.

Threat Intelligence Enrichment

mukul975

Automate IOC enrichment in Splunk for enhanced security.

Security & ComplianceintermediatePython27.6k repo

Implementing SIEM Use Cases

mukul975

Enhance SIEM detection with structured use case implementation.

Security & ComplianceintermediatePython · Shell27.6k repo

Building Detection Rules with Sigma

mukul975

Create portable detection rules for SIEM platforms.

Security & ComplianceintermediatePython · Shell27.6k repo

Detecting Lateral Movement with Splunk

mukul975

Hunt for adversary lateral movement using Splunk.

Security & ComplianceintermediatePython27.6k repo

SIEM Use Case Tuning

mukul975

Reduce alert fatigue in your SIEM environment.

Security & ComplianceintermediatePython27.6k repo

Investigating Phishing Email Incident

Investigates phishing email incidents from initial user report through header analysis, URL/attachment detonation, impacted user identification, and containment actions using SOC tools like Splunk, Microsoft Defender, and sandbox analysis platforms. Use when a reported phishing email requires full incident investigation to determine scope and impact.

Building Incident Response Dashboard

Builds real-time incident response dashboards in Splunk, Elastic, or Grafana to provide SOC analysts and leadership with situational awareness during active incidents, tracking affected systems, containment status, IOC spread, and response timeline. Use when IR teams need unified visibility during incident coordination and post-incident reporting.

Building Detection Rules with Splunk SPL

Build effective detection rules using Splunk Search Processing Language (SPL) correlation searches to identify security threats in SOC environments.

Analyzing Windows Event Logs in Splunk

Analyzes Windows Security, System, and Sysmon event logs in Splunk to detect authentication attacks, privilege escalation, persistence mechanisms, and lateral movement using SPL queries mapped to MITRE ATT&CK techniques. Use when SOC analysts need to investigate Windows-based threats, build detection queries, or perform forensic timeline analysis of Windows endpoints and domain controllers.

Analyzing Security Logs with Splunk

Leverages Splunk Enterprise Security and SPL (Search Processing Language) to investigate security incidents through log correlation, timeline reconstruction, and anomaly detection. Covers Windows event logs, firewall logs, proxy logs, and authentication data analysis. Activates for requests involving Splunk investigation, SPL queries, SIEM log analysis, security event correlation, or log-based incident investigation.