Splunk skills
Free agent skills tagged splunk, ready to install into any SKILL.md-compatible agent.
10 skills
Threat Intelligence Enrichment
mukul975
Automate IOC enrichment in Splunk for enhanced security.
Implementing SIEM Use Cases
mukul975
Enhance SIEM detection with structured use case implementation.
Building Detection Rules with Sigma
mukul975
Create portable detection rules for SIEM platforms.
Detecting Lateral Movement with Splunk
mukul975
Hunt for adversary lateral movement using Splunk.
SIEM Use Case Tuning
mukul975
Reduce alert fatigue in your SIEM environment.
Investigating Phishing Email Incident
Investigates phishing email incidents from initial user report through header analysis, URL/attachment detonation, impacted user identification, and containment actions using SOC tools like Splunk, Microsoft Defender, and sandbox analysis platforms. Use when a reported phishing email requires full incident investigation to determine scope and impact.
Building Incident Response Dashboard
Builds real-time incident response dashboards in Splunk, Elastic, or Grafana to provide SOC analysts and leadership with situational awareness during active incidents, tracking affected systems, containment status, IOC spread, and response timeline. Use when IR teams need unified visibility during incident coordination and post-incident reporting.
Building Detection Rules with Splunk SPL
Build effective detection rules using Splunk Search Processing Language (SPL) correlation searches to identify security threats in SOC environments.
Analyzing Windows Event Logs in Splunk
Analyzes Windows Security, System, and Sysmon event logs in Splunk to detect authentication attacks, privilege escalation, persistence mechanisms, and lateral movement using SPL queries mapped to MITRE ATT&CK techniques. Use when SOC analysts need to investigate Windows-based threats, build detection queries, or perform forensic timeline analysis of Windows endpoints and domain controllers.
Analyzing Security Logs with Splunk
Leverages Splunk Enterprise Security and SPL (Search Processing Language) to investigate security incidents through log correlation, timeline reconstruction, and anomaly detection. Covers Windows event logs, firewall logs, proxy logs, and authentication data analysis. Activates for requests involving Splunk investigation, SPL queries, SIEM log analysis, security event correlation, or log-based incident investigation.
