★ 0 · Updated 2026-09-20
Triages security alerts in Splunk Enterprise Security by classifying severity, investigating events, correlating telemetry, and making escalation decisions.
Browse skills that share this tag.
★ 0 · Updated 2026-09-20
Triages security alerts in Splunk Enterprise Security by classifying severity, investigating events, correlating telemetry, and making escalation decisions.
★ 0 · Updated 2026-09-19
Reduces SIEM false positives through rule tuning, threshold adjustment, correlation logic refinement, allowlisting, and threat intelligence enrichment.
★ 0 · Updated 2026-09-19
Reduces SIEM false positives through systematic rule tuning, threshold adjustment, correlation logic refinement, allowlisting, and threat intelligence enrichment.
★ 0 · Updated 2026-09-19
Reduces SIEM false positives through systematic rule tuning, threshold adjustment, correlation logic refinement, allowlisting, and threat intelligence enrichment.
★ 70 · Updated 2026-09-19
Reduces SIEM false positives through rule tuning, threshold adjustment, correlation refinement, allowlisting, and threat intelligence enrichment.
★ 0 · Updated 2026-09-16
Proactively hunts for adversary abuse of signed system binaries (LOLBins) used to execute payloads, download files, or proxy execution.
★ 0 · Updated 2026-09-16
Proactively hunts for adversary abuse of signed system binaries (LOLBins) used to execute malicious payloads or evade defense controls.
★ 0 · Updated 2026-09-16
Proactively hunts for adversary abuse of signed system binaries to execute payloads, download files, or proxy execution.
★ 1 · Updated 2026-09-15
Provides reference details on Notion Enterprise audit log event categories, SIEM streaming setup, filtering options, and CSV export procedures.
★ 0 · Updated 2026-09-12
Build multi-event correlation rules using Splunk SPL and Sigma to detect APT lateral movement across Windows systems.
★ 1 · Updated 2026-09-12
Build multi-event correlation rules using Splunk SPL and Sigma to detect APT lateral movement across Windows event logs and Sysmon telemetry.
★ 64 · Updated 2026-06-30
Correlates security events in IBM QRadar SIEM using AQL and custom rules to detect multi-stage attacks
★ 4 · Updated 2026-05-09
Classifies severity, investigates notable events, correlates telemetry, and makes triage decisions in Splunk Enterprise Security
★ 327 · Updated 2026-05-09
Classify severity, investigate notable events, correlate telemetry in Splunk Enterprise Security
★ 3,613 · Updated 2026-05-09
Triage security alerts in Splunk ES by classifying severity, investigating events, and making disposition decisions
★ 18 · Updated 2026-02-11
Expert guidance for proactive threat hunting to identify undetected threats
★ 528 · Updated 2026-02-11
Provides expert guidance for proactive threat hunting in security environments