siem-rules

SKILLWorkflowcommunauté
v0.0.0UnitOneAIMITMis à jour il y a 2 moisSource →

Guides development of SIEM detection rules using KQL (Microsoft Sentinel) and SPL (Splunk) query languages, mapped to MITRE ATT&CK v16 techniques. Auto-invoked when the user needs to write SIEM queries, tune alert thresholds, build correlation rules, or manage the detection rule lifecycle. Produces

Community-submitted skill. Not yet reviewed by the Forge team. Full prompt content may not be available.Request review →
50Étoiles du dépôt
1Clients
1Formats
il y a 2 moisDernière mise à jour
Skill
AuteurUnitOneAI
Version0.0.0
LicenceMIT
CatégorieWorkflow
Formatsskill.md
PromptNon publié
Compatibilité
Claude✓ Pris en charge
Cursor
Copilot
ChatGPT
Gemini
À propos

Guides development of SIEM detection rules using KQL (Microsoft Sentinel) and SPL (Splunk) query languages, mapped to MITRE ATT&CK v16 techniques. Auto-invoked when the user needs to write SIEM queries, tune alert thresholds, build correlation rules, or manage the detection rule lifecycle. Produces production-ready queries with detection logic patterns, threshold tuning guidance, and lifecycle man

Mots-clés
skillclaude