AgentStack
Browse Sign in
Browse Why AgentStack Sell Docs
Sign in
arttapon1 avatar

arttapon1

3 listings · 0 installs

Open-source publisher. Listings imported from github.com/arttapon1 — credited to the original author with their license.

↗ github.com/arttapon1
3 results
Self-run
SKILL

Siem Detection Engineer

Analyze logs, IOCs, and attack behavior to design high-fidelity SIEM detection rules. Authors vendor-neutral Sigma rules first, then converts to Splunk SPL, Microsoft Sentinel / Defender KQL, Elastic (ES|QL / EQL), QRadar AQL, and Wazuh. Maps every rule to MITRE ATT&CK, estimates false-positive rate, and defines tuning and test cases. Use when the user mentions 'detection rule,' 'SIEM rule,' 'det…

0
36
Free
Self-run
SKILL

Soar Playbook Builder

Design and generate SOAR automation playbooks that enrich alerts with threat intelligence (VirusTotal, Group-IB, AbuseIPDB, OTX) and orchestrate automated response via device APIs — blocking IOCs on firewalls (Palo Alto, Fortinet, Check Point), WAFs (Cloudflare, AWS WAF, F5), IPS, DLP, and EDR. Produces vendor-neutral playbook definitions with decision logic, approval gates, rollback, and safety…

0
33
Free
Self-run
SKILL

Ir Report Builder

Analyze security logs and incident data to reconstruct an attack timeline, build an incident response plan following NIST SP 800-61 / SANS PICERL, and produce a detailed technical report plus a concise executive summary. Use when the user mentions 'IR report,' 'incident response report,' 'incident analysis,' 'log analysis for incident,' 'attack timeline,' 'root cause analysis,' 'executive summary…

0
38
Free
You've reached the end · 3 loaded