LogoClawIndex
CasesSkillsAbout
LogoClawIndex

ClawIndex

OpenClaw Skills & Use Case Index

ClawIndex is an ecosystem-driven index of OpenClaw skills and real-world use cases.

Index

Skills·
Cases

Meta

About·
Disclaimer·
Email·
GitHub
© 2026 ClawIndex All Rights Reserved.

Skills tagged: siem

Browse skills that share this tag.

  • triaging-security-alerts-in-splunk - Triage security alerts in Splunk Enterprise Security
    socsplunkalert-triagesiem

    ★ 0 · Updated 2026-09-20

    Triages security alerts in Splunk Enterprise Security by classifying severity, investigating events, correlating telemetry, and making escalation decisions.

    ⚙ Classify alert severity⚙ Investigate notable event context⚙ Correlate telemetry across sources
  • performing-false-positive-reduction-in-siem - Performing False Positive Reduction in SIEM
    siemfalse-positivealert-tuningdetection-engineering

    ★ 0 · Updated 2026-09-19

    Reduces SIEM false positives through rule tuning, threshold adjustment, correlation logic refinement, allowlisting, and threat intelligence enrichment.

    ⚙ Identify noisy SIEM rules⚙ Tune detection rule alert thresholds⚙ Manage allowlists and exclusion lookups
  • performing-false-positive-reduction-in-siem - Reduce SIEM false positives using rule tuning and analytics.
    siemfalse-positivealert-tuningdetection-engineering

    ★ 0 · Updated 2026-09-19

    Reduces SIEM false positives through systematic rule tuning, threshold adjustment, correlation logic refinement, allowlisting, and threat intelligence enrichment.

    ⚙ Identify noisy correlation search rules⚙ Adjust alert detection thresholds⚙ Apply allowlists for benign sources
  • performing-false-positive-reduction-in-siem - Performing False Positive Reduction in SIEM
    siemfalse-positivealert-tuningdetection-engineering

    ★ 0 · Updated 2026-09-19

    Reduces SIEM false positives through systematic rule tuning, threshold adjustment, correlation logic refinement, allowlisting, and threat intelligence enrichment.

    ⚙ Identify noisiest SIEM rules⚙ Tune detection alert thresholds⚙ Manage allowlists and exclusions
  • performing-false-positive-reduction-in-siem - Performing False Positive Reduction in SIEM
    siemfalse-positivealert-tuningdetection-engineering

    ★ 70 · Updated 2026-09-19

    Reduces SIEM false positives through rule tuning, threshold adjustment, correlation refinement, allowlisting, and threat intelligence enrichment.

    ⚙ Identify high-volume noisy rules⚙ Adjust rule triggering thresholds⚙ Manage allowlists and exclusions
  • hunting-for-living-off-the-land-binaries - Hunting for Living-off-the-Land Binaries (LOLBins)
    threat-huntingmitre-attacklolbinsedr

    ★ 0 · Updated 2026-09-16

    Proactively hunts for adversary abuse of signed system binaries (LOLBins) used to execute payloads, download files, or proxy execution.

    ⚙ Define hunt hypothesis⚙ Identify target LOLBins⚙ Collect process telemetry
  • hunting-for-living-off-the-land-binaries - Hunt for adversary abuse of signed system binaries (LOLBins)
    threat-huntingmitre-attacklolbinsedr

    ★ 0 · Updated 2026-09-16

    Proactively hunts for adversary abuse of signed system binaries (LOLBins) used to execute malicious payloads or evade defense controls.

    ⚙ Define hunt hypotheses⚙ Identify target LOLBins⚙ Collect process telemetry
  • hunting-for-living-off-the-land-binaries - Hunting for Living-off-the-Land Binaries (LOLBins)
    threat-huntinglolbinsdefense-evasionedr

    ★ 0 · Updated 2026-09-16

    Proactively hunts for adversary abuse of signed system binaries to execute payloads, download files, or proxy execution.

    ⚙ Define hunt hypothesis⚙ Identify target LOLBins⚙ Collect process telemetry
  • notion-audit-log - Reference guide for Notion Enterprise audit log and SIEM
    notionaudit-logsiemsecurity

    ★ 1 · Updated 2026-09-15

    Provides reference details on Notion Enterprise audit log event categories, SIEM streaming setup, filtering options, and CSV export procedures.

    ⚙ Audit workspace security events⚙ Configure custom SIEM integration⚙ Filter audit log events
  • implementing-siem-correlation-rules-for-apt - Implement SIEM correlation rules for APT lateral movement.
    siemcorrelation-rulesapt-detectionlateral-movement

    ★ 0 · Updated 2026-09-12

    Build multi-event correlation rules using Splunk SPL and Sigma to detect APT lateral movement across Windows systems.

    ⚙ Connect to Splunk REST API⚙ Build Sigma correlation rules⚙ Convert Sigma rules to SPL
  • implementing-siem-correlation-rules-for-apt - Implementing SIEM Correlation Rules for APT
    siemcorrelation-rulesapt-detectionlateral-movement

    ★ 1 · Updated 2026-09-12

    Build multi-event correlation rules using Splunk SPL and Sigma to detect APT lateral movement across Windows event logs and Sysmon telemetry.

    ⚙ Build multi-step Sigma correlation rules⚙ Convert Sigma rules to Splunk SPL⚙ Deploy correlation searches to Splunk ES
  • correlating-security-events-in-qradar - QRadar Security Event Correlation
    cybersecuritysiemqradaraql

    ★ 64 · Updated 2026-06-30

    Correlates security events in IBM QRadar SIEM using AQL and custom rules to detect multi-stage attacks

    ⚙ investigate QRadar offenses⚙ query events using AQL⚙ build correlation rules
  • triaging-security-alerts-in-splunk - Triaging Security Alerts in Splunk ES
    socsiemsplunkalert-triage

    ★ 4 · Updated 2026-05-09

    Classifies severity, investigates notable events, correlates telemetry, and makes triage decisions in Splunk Enterprise Security

    ⚙ access incident review dashboard⚙ prioritize notable events⚙ investigate event context
  • triaging-security-alerts-in-splunk - Splunk Security Alert Triage
    socsplunkalert-triagesiem

    ★ 327 · Updated 2026-05-09

    Classify severity, investigate notable events, correlate telemetry in Splunk Enterprise Security

    ⚙ access incident review dashboard⚙ investigate notable events⚙ correlate data sources
  • triaging-security-alerts-in-splunk - Splunk Security Alert Triage for SOC
    socsplunkalert-triagesiem

    ★ 3,613 · Updated 2026-05-09

    Triage security alerts in Splunk ES by classifying severity, investigating events, and making disposition decisions

    ⚙ access Incident Review dashboard⚙ prioritize notable events⚙ investigate event context
  • secops-hunt - Proactive Threat Hunting for Security Operations
    securitythreat-huntingiocttp

    ★ 18 · Updated 2026-02-11

    Expert guidance for proactive threat hunting to identify undetected threats

    ⚙ check indicator matches⚙ search security events⚙ query UDM data
  • secops-hunt - Proactive Threat Hunting Guidance for Security Operations
    securitythreat-huntingincident-responsesiem

    ★ 528 · Updated 2026-02-11

    Provides expert guidance for proactive threat hunting in security environments

    ⚙ hunt for threat campaigns⚙ search for IOCs⚙ investigate TTPs