siem-rules

SKILLFlusso di lavorocommunity
v0.0.0UnitOneAIMITAggiornato 2 mesi faFonte →

Guides development of SIEM detection rules using KQL (Microsoft Sentinel) and SPL (Splunk) query languages, mapped to MITRE ATT&CK v16 techniques. Auto-invoked when the user needs to write SIEM queries, tune alert thresholds, build correlation rules, or manage the detection rule lifecycle. Produces

Community-submitted skill. Not yet reviewed by the Forge team. Full prompt content may not be available.Request review →
50Stelle del repo
1Client
1Formati
2 mesi faUltimo aggiornamento
Skill
AutoreUnitOneAI
Versione0.0.0
LicenzaMIT
CategoriaFlusso di lavoro
Formatiskill.md
PromptNon pubblicato
Compatibilità
Claude✓ Supportato
Cursor
Copilot
ChatGPT
Gemini
Descrizione

Guides development of SIEM detection rules using KQL (Microsoft Sentinel) and SPL (Splunk) query languages, mapped to MITRE ATT&CK v16 techniques. Auto-invoked when the user needs to write SIEM queries, tune alert thresholds, build correlation rules, or manage the detection rule lifecycle. Produces production-ready queries with detection logic patterns, threshold tuning guidance, and lifecycle man

Parole chiave
skillclaude