siem-rules

SKILLWorkflowCommunity
v0.0.0UnitOneAIMITAktualisiert vor 2 Mon.Quelle →

Guides development of SIEM detection rules using KQL (Microsoft Sentinel) and SPL (Splunk) query languages, mapped to MITRE ATT&CK v16 techniques. Auto-invoked when the user needs to write SIEM queries, tune alert thresholds, build correlation rules, or manage the detection rule lifecycle. Produces

Community-submitted skill. Not yet reviewed by the Forge team. Full prompt content may not be available.Request review →
50Repo-Sterne
1Clients
1Formate
vor 2 Mon.Letzte Aktualisierung
Skill
AutorUnitOneAI
Version0.0.0
LizenzMIT
KategorieWorkflow
Formateskill.md
PromptNicht veröffentlicht
Kompatibilität
Claude✓ Unterstützt
Cursor
Copilot
ChatGPT
Gemini
Über

Guides development of SIEM detection rules using KQL (Microsoft Sentinel) and SPL (Splunk) query languages, mapped to MITRE ATT&CK v16 techniques. Auto-invoked when the user needs to write SIEM queries, tune alert thresholds, build correlation rules, or manage the detection rule lifecycle. Produces production-ready queries with detection logic patterns, threshold tuning guidance, and lifecycle man

Schlagwörter
skillclaude