siem-rules

SKILLFlujo de trabajocomunidad
v0.0.0UnitOneAIMITActualizado hace 2 mFuente →

Guides development of SIEM detection rules using KQL (Microsoft Sentinel) and SPL (Splunk) query languages, mapped to MITRE ATT&CK v16 techniques. Auto-invoked when the user needs to write SIEM queries, tune alert thresholds, build correlation rules, or manage the detection rule lifecycle. Produces

Community-submitted skill. Not yet reviewed by the Forge team. Full prompt content may not be available.Request review →
50Estrellas del repo
1Clientes
1Formatos
hace 2 mÚltima actualización
Skill
AutorUnitOneAI
Versión0.0.0
LicenciaMIT
CategoríaFlujo de trabajo
Formatosskill.md
PromptNo publicado
Compatibilidad
Claude✓ Compatible
Cursor
Copilot
ChatGPT
Gemini
Acerca de

Guides development of SIEM detection rules using KQL (Microsoft Sentinel) and SPL (Splunk) query languages, mapped to MITRE ATT&CK v16 techniques. Auto-invoked when the user needs to write SIEM queries, tune alert thresholds, build correlation rules, or manage the detection rule lifecycle. Produces production-ready queries with detection logic patterns, threshold tuning guidance, and lifecycle man

Palabras clave
skillclaude