tag

splunk

16 indexed skills · max 10 per page

skills (16)

detecting-lateral-movement-with-splunk

mukul975/Anthropic-Cybersecurity-Skills · detecting-lateral-movement-with-splunk

0

Detect adversary lateral movement across networks using Splunk SPL queries against Windows authentication logs, SMB traffic, and remote service abuse.

detecting-golden-ticket-forgery

mukul975/Anthropic-Cybersecurity-Skills · detecting-golden-ticket-forgery

0

Detect Kerberos Golden Ticket forgery by analyzing Windows Event ID 4769 for RC4 encryption downgrades (0x17), abnormal ticket lifetimes, and krbtgt account anomalies in Splunk and Elastic SIEM

building-threat-intelligence-enrichment-in-splunk

mukul975/Anthropic-Cybersecurity-Skills · building-threat-intelligence-enrichment-in-splunk

0

Build automated threat intelligence enrichment pipelines in Splunk Enterprise Security using lookup tables, modular inputs, and the Threat Intelligence Framework.

building-detection-rules-with-sigma

mukul975/Anthropic-Cybersecurity-Skills · building-detection-rules-with-sigma

0

Builds vendor-agnostic detection rules using the Sigma rule format for threat detection across SIEM platforms including Splunk, Elastic, and Microsoft Sentinel. Use when creating portable detection logic from threat intelligence, mapping rules to MITRE ATT&CK techniques, or converting community Sigma rules into platform-specific queries using sigmac or pySigma backends.

analyzing-security-logs-with-splunk

mukul975/Anthropic-Cybersecurity-Skills · analyzing-security-logs-with-splunk

0

Leverages Splunk Enterprise Security and SPL (Search Processing Language) to investigate security incidents through log correlation, timeline reconstruction, and anomaly detection. Covers Windows event logs, firewall logs, proxy logs, and authentication data analysis. Activates for requests involving Splunk investigation, SPL queries, SIEM log analysis, security event correlation, or log-based incident investigation.

analyzing-dns-logs-for-exfiltration

mukul975/Anthropic-Cybersecurity-Skills · analyzing-dns-logs-for-exfiltration

0

Analyzes DNS query logs to detect data exfiltration via DNS tunneling, DGA domain communication, and covert C2 channels using entropy analysis, query volume anomalies, and subdomain length detection in SIEM platforms. Use when SOC teams need to identify DNS-based threats that bypass traditional network security controls.

prevpage 2 / 2next