LogoClawIndex
CasesSkillsAbout
LogoClawIndex

ClawIndex

OpenClaw Skills & Use Case Index

ClawIndex is an ecosystem-driven index of OpenClaw skills and real-world use cases.

Index

Skills·
Cases

Meta

About·
Disclaimer·
Email·
GitHub
© 2026 ClawIndex All Rights Reserved.

Skills tagged: soc

Browse skills that share this tag.

  • triaging-security-alerts-in-splunk - Triage security alerts in Splunk Enterprise Security
    socsplunkalert-triagesiem

    ★ 0 · Updated 2026-09-20

    Triages security alerts in Splunk Enterprise Security by classifying severity, investigating events, correlating telemetry, and making escalation decisions.

    ⚙ Classify alert severity⚙ Investigate notable event context⚙ Correlate telemetry across sources
  • triaging-security-incident-with-ir-playbook - Triaging Security Incidents with IR Playbooks
    incident-responsetriageplaybookseverity-classification

    ★ 0 · Updated 2026-09-20

    Classify and prioritize security incidents using structured IR playbooks to determine severity, assign response teams, and initiate response procedures.

    ⚙ Acknowledge security alerts⚙ Enrich alert indicator data⚙ Classify security incident types
  • performing-false-positive-reduction-in-siem - Performing False Positive Reduction in SIEM
    siemfalse-positivealert-tuningdetection-engineering

    ★ 0 · Updated 2026-09-19

    Reduces SIEM false positives through rule tuning, threshold adjustment, correlation logic refinement, allowlisting, and threat intelligence enrichment.

    ⚙ Identify noisy SIEM rules⚙ Tune detection rule alert thresholds⚙ Manage allowlists and exclusion lookups
  • performing-false-positive-reduction-in-siem - Reduce SIEM false positives using rule tuning and analytics.
    siemfalse-positivealert-tuningdetection-engineering

    ★ 0 · Updated 2026-09-19

    Reduces SIEM false positives through systematic rule tuning, threshold adjustment, correlation logic refinement, allowlisting, and threat intelligence enrichment.

    ⚙ Identify noisy correlation search rules⚙ Adjust alert detection thresholds⚙ Apply allowlists for benign sources
  • performing-false-positive-reduction-in-siem - Performing False Positive Reduction in SIEM
    siemfalse-positivealert-tuningdetection-engineering

    ★ 0 · Updated 2026-09-19

    Reduces SIEM false positives through systematic rule tuning, threshold adjustment, correlation logic refinement, allowlisting, and threat intelligence enrichment.

    ⚙ Identify noisiest SIEM rules⚙ Tune detection alert thresholds⚙ Manage allowlists and exclusions
  • performing-false-positive-reduction-in-siem - Performing False Positive Reduction in SIEM
    siemfalse-positivealert-tuningdetection-engineering

    ★ 70 · Updated 2026-09-19

    Reduces SIEM false positives through rule tuning, threshold adjustment, correlation refinement, allowlisting, and threat intelligence enrichment.

    ⚙ Identify high-volume noisy rules⚙ Adjust rule triggering thresholds⚙ Manage allowlists and exclusions
  • correlating-security-events-in-qradar - QRadar Security Event Correlation
    cybersecuritysiemqradaraql

    ★ 64 · Updated 2026-06-30

    Correlates security events in IBM QRadar SIEM using AQL and custom rules to detect multi-stage attacks

    ⚙ investigate QRadar offenses⚙ query events using AQL⚙ build correlation rules
  • triaging-security-alerts-in-splunk - Triaging Security Alerts in Splunk ES
    socsiemsplunkalert-triage

    ★ 4 · Updated 2026-05-09

    Classifies severity, investigates notable events, correlates telemetry, and makes triage decisions in Splunk Enterprise Security

    ⚙ access incident review dashboard⚙ prioritize notable events⚙ investigate event context
  • triaging-security-alerts-in-splunk - Splunk Security Alert Triage
    socsplunkalert-triagesiem

    ★ 327 · Updated 2026-05-09

    Classify severity, investigate notable events, correlate telemetry in Splunk Enterprise Security

    ⚙ access incident review dashboard⚙ investigate notable events⚙ correlate data sources
  • triaging-security-alerts-in-splunk - Splunk Security Alert Triage for SOC
    socsplunkalert-triagesiem

    ★ 3,613 · Updated 2026-05-09

    Triage security alerts in Splunk ES by classifying severity, investigating events, and making disposition decisions

    ⚙ access Incident Review dashboard⚙ prioritize notable events⚙ investigate event context