tag

soc

34 indexed skills · max 10 per page

skills (34)

performing-lateral-movement-detection

mukul975/Anthropic-Cybersecurity-Skills · performing-lateral-movement-detection

0

Detects lateral movement techniques including Pass-the-Hash, PsExec, WMI execution, RDP pivoting, and SMB-based spreading using SIEM correlation of Windows event logs, network flow data, and endpoint telemetry mapped to MITRE ATT&CK Lateral Movement (TA0008) techniques.

implementing-siem-use-case-tuning

mukul975/Anthropic-Cybersecurity-Skills · implementing-siem-use-case-tuning

0

Tune SIEM detection rules to reduce false positives by analyzing alert volumes, creating whitelists, adjusting thresholds, and measuring detection efficacy metrics in Splunk and Elastic

triaging-security-alerts-in-splunk

mukul975/Anthropic-Cybersecurity-Skills · triaging-security-alerts-in-splunk

0

Triages security alerts in Splunk Enterprise Security by classifying severity, investigating notable events, correlating related telemetry, and making escalation or closure decisions using SPL queries and the Incident Review dashboard. Use when SOC analysts face queued alerts from correlation searches, need to prioritize investigation order, or must document triage decisions for handoff to Tier 2/3 analysts.

implementing-siem-use-cases-for-detection

mukul975/Anthropic-Cybersecurity-Skills · implementing-siem-use-cases-for-detection

0

Implements SIEM detection use cases by designing correlation rules, threshold alerts, and behavioral analytics mapped to MITRE ATT&CK techniques across Splunk, Elastic, and Sentinel. Use when SOC teams need to expand detection coverage, formalize use case lifecycle management, or build a detection library aligned to organizational threat profile.

triaging-security-incident-with-ir-playbook

mukul975/Anthropic-Cybersecurity-Skills · triaging-security-incident-with-ir-playbook

0

Classify and prioritize security incidents using structured IR playbooks to determine severity, assign response teams, and initiate appropriate response procedures.

investigating-phishing-email-incident

mukul975/Anthropic-Cybersecurity-Skills · investigating-phishing-email-incident

0

Investigates phishing email incidents from initial user report through header analysis, URL/attachment detonation, impacted user identification, and containment actions using SOC tools like Splunk, Microsoft Defender, and sandbox analysis platforms. Use when a reported phishing email requires full incident investigation to determine scope and impact.

building-soc-playbook-for-ransomware

mukul975/Anthropic-Cybersecurity-Skills · building-soc-playbook-for-ransomware

0

Builds a structured SOC incident response playbook for ransomware attacks covering detection, containment, eradication, and recovery phases with specific SIEM queries, isolation procedures, and decision trees. Use when SOC teams need formalized response procedures for ransomware incidents aligned to NIST SP 800-61 and MITRE ATT&CK ransomware techniques.

implementing-ticketing-system-for-incidents

mukul975/Anthropic-Cybersecurity-Skills · implementing-ticketing-system-for-incidents

0

Implements an integrated incident ticketing system connecting SIEM alerts to ServiceNow, Jira, or TheHive for structured incident tracking, SLA management, escalation workflows, and compliance documentation. Use when SOC teams need formalized incident lifecycle management with automated ticket creation, assignment routing, and resolution tracking.

building-soc-metrics-and-kpi-tracking

mukul975/Anthropic-Cybersecurity-Skills · building-soc-metrics-and-kpi-tracking

0

Builds SOC performance metrics and KPI tracking dashboards measuring Mean Time to Detect (MTTD), Mean Time to Respond (MTTR), alert quality ratios, analyst productivity, and detection coverage using SIEM data. Use when SOC leadership needs operational visibility, continuous improvement tracking, or executive-level reporting on security operations effectiveness.

investigating-insider-threat-indicators

mukul975/Anthropic-Cybersecurity-Skills · investigating-insider-threat-indicators

0

Investigates insider threat indicators including data exfiltration attempts, unauthorized access patterns, policy violations, and pre-departure behaviors using SIEM analytics, DLP alerts, and HR data correlation. Use when SOC teams receive insider threat referrals from HR, detect anomalous data movement by employees, or need to build investigation timelines for potential insider threats.

prevpage 2 / 4next