explainx.ainewsletter3.5k
TrendingNewsPathwaysSkills
Pricing
explainx.ai

Upskill in AI — 16 free pathways, live workshops & bootcamps, and 50+ courses from practitioners. Plus the skills, tools, and MCP servers to practice on.

follow us

corporate training

support@explainx.ai

get started

Find your pathTake Free Evaluation

learn

pathways — start freeworkshopsbootcampscoursescertificationsmock testsexplainx universitycorporate traininglearn skills & mcp

discover

skillsmcp serversexplainx mcptoolsagentsllmsdesignsdictionaryagi trackerranks

company

aboutvisionmissionteaminstructorscommunityhackathonscareers

content

daily AI newsstate of AI — live resultsblogreleasespromptsgeneratorsresource libraryfor LLMsexplainx.ai kids

solutions

all solutionsdeveloper upskillingmarketing upskillingproduct manager upskillingleadership upskilling

newsletter · weekly

Get AI news, tools, and insights in your inbox.

supportprivacytermsdata rightshow we create contentsubmission guidelines

© 2026 AISOLO Technologies Pvt Ltd

home/skills/tag/siem
skill tag

siem▌

24 indexed skills · max 10 per page

skills (24)

correlating-security-events-in-qradar

mukul975/Anthropic-Cybersecurity-Skills · correlating-security-events-in-qradar

1

Correlates security events in IBM QRadar SIEM using AQL (Ariel Query Language), custom rules, building blocks, and offense management to detect multi-stage attacks across network, endpoint, and application log sources. Use when SOC analysts need to investigate QRadar offenses, build correlation rules, or tune detection logic for reducing false positives.

performing-alert-triage-with-elastic-siem

mukul975/Anthropic-Cybersecurity-Skills · performing-alert-triage-with-elastic-siem

0

Perform systematic alert triage in Elastic Security SIEM to rapidly classify, prioritize, and investigate security alerts for SOC operations.

performing-threat-hunting-with-elastic-siem

mukul975/Anthropic-Cybersecurity-Skills · performing-threat-hunting-with-elastic-siem

0

Performs proactive threat hunting in Elastic Security SIEM using KQL/EQL queries, detection rules, and Timeline investigation to identify threats that evade automated detection. Use when SOC teams need to hunt for specific ATT&CK techniques, investigate anomalous behaviors, or validate detection coverage gaps using Elasticsearch and Kibana Security.

implementing-siem-correlation-rules-for-apt

mukul975/Anthropic-Cybersecurity-Skills · implementing-siem-correlation-rules-for-apt

0

Write multi-event correlation rules that detect APT lateral movement by chaining Windows authentication events, process execution telemetry, and network connection logs across hosts. Uses Splunk SPL and Sigma rule format to correlate Event IDs 4624, 4648, 4688, and Sysmon Events 1/3 within sliding time windows to surface attack sequences invisible to single-event detections.

detecting-lateral-movement-in-network

mukul975/Anthropic-Cybersecurity-Skills · detecting-lateral-movement-in-network

0

Identifies lateral movement techniques in enterprise networks by analyzing authentication logs, network flows, SMB traffic, and RDP sessions using Zeek, Velociraptor, and SIEM correlation rules to detect attackers moving between systems.

performing-false-positive-reduction-in-siem

mukul975/Anthropic-Cybersecurity-Skills · performing-false-positive-reduction-in-siem

0

Perform systematic SIEM false positive reduction through rule tuning, threshold adjustment, correlation refinement, and threat intelligence enrichment to combat alert fatigue.

detecting-rdp-brute-force-attacks

mukul975/Anthropic-Cybersecurity-Skills · detecting-rdp-brute-force-attacks

0

Detect RDP brute force attacks by analyzing Windows Security Event Logs for failed authentication patterns (Event ID 4625), successful logons after failures (Event ID 4624), NLA failures, and source IP frequency analysis.

implementing-security-monitoring-with-datadog

mukul975/Anthropic-Cybersecurity-Skills · implementing-security-monitoring-with-datadog

0

Implements security monitoring using Datadog Cloud SIEM, Cloud Security Management (CSM), and Workload Protection to detect threats, enforce compliance, and respond to security events across cloud and hybrid infrastructure. Covers Agent deployment, log source ingestion, detection rule creation, security dashboards, and automated notification workflows. Activates for requests involving Datadog security setup, Cloud SIEM configuration, CSM threat detection, or security monitoring dashboards.

building-detection-rule-with-splunk-spl

mukul975/Anthropic-Cybersecurity-Skills · building-detection-rule-with-splunk-spl

0

Build effective detection rules using Splunk Search Processing Language (SPL) correlation searches to identify security threats in SOC environments.

implementing-alert-fatigue-reduction

mukul975/Anthropic-Cybersecurity-Skills · implementing-alert-fatigue-reduction

0

Implements strategies to reduce SOC alert fatigue by tuning detection rules, consolidating duplicate alerts, implementing risk-based alerting, and measuring alert quality metrics to maintain analyst effectiveness and prevent critical alert dismissal. Use when SOC teams face overwhelming alert volumes, high false positive rates, or declining analyst performance.

prevpage 1 / 3next