# willwebster5

> Open-source publisher. Listings imported from github.com/willwebster5 — credited to the original author with their license.

- **Listings:** 10
- **Total installs:** 0
- **Profile:** https://agentstack.voostack.com/s/willwebster5
- **Website:** https://github.com/willwebster5

## Published listings

- [Soc Agents](https://agentstack.voostack.com/l/skill-willwebster5-agent-skills-soc-agents) — Skill · Free · security-reviewed — `agentstack add skill-willwebster5-agent-skills-soc-agents`
  Unified SOC analyst workflow for CrowdStrike NGSIEM — triage alerts, investigate security events, hunt threats, and tune detections. Agent-delegated architecture: Haiku for mechanical tasks, Sonnet for substantive work, Opus for judgment.
- [Source Threat Modeling](https://agentstack.voostack.com/l/skill-willwebster5-agent-skills-source-threat-modeling) — Skill · Free · security-reviewed — `agentstack add skill-willwebster5-agent-skills-source-threat-modeling`
  >
- [Threat Hunting](https://agentstack.voostack.com/l/skill-willwebster5-agent-skills-threat-hunting) — Skill · Free · security-reviewed — `agentstack add skill-willwebster5-agent-skills-threat-hunting`
  Autonomous threat hunting using the PEAK framework (Prepare → Execute → Act). Executes hypothesis-driven, intelligence-driven, and baseline hunts against CrowdStrike NG-SIEM. Produces hunt reports, detection backlogs, and visibility gap reports. Use when proactively hunting for threats, validating detection coverage, or responding to new threat intelligence.
- [Detection Tuning](https://agentstack.voostack.com/l/skill-willwebster5-agent-skills-detection-tuning) — Skill · Free · security-reviewed — `agentstack add skill-willwebster5-agent-skills-detection-tuning`
  Analyze CrowdStrike NGSIEM detections for tuning opportunities based on environmental context, recent false positives, and available enrichment functions. Use when tuning detections (including behavioral rules with correlate()), reducing false positives, enhancing detection coverage, or reviewing OOTB templates for production deployment.
- [Logscale Security Queries](https://agentstack.voostack.com/l/skill-willwebster5-agent-skills-logscale-security-queries) — Skill · Free — `agentstack add skill-willwebster5-agent-skills-logscale-security-queries`
  Develop, optimize, and troubleshoot CrowdStrike LogScale (Humio) security detection queries using CQL syntax. Use when writing LogScale queries, building security detections, creating threat hunting rules, fixing CQL syntax errors, working with CrowdStrike EDR/Falcon security monitoring, or building behavioral rules with the correlate() function. Handles case statements, risk categorization, mult…
- [Response Playbooks](https://agentstack.voostack.com/l/skill-willwebster5-agent-skills-response-playbooks) — Skill · Free · security-reviewed — `agentstack add skill-willwebster5-agent-skills-response-playbooks`
  >
- [Cql Patterns](https://agentstack.voostack.com/l/skill-willwebster5-agent-skills-cql-patterns) — Skill · Free · security-reviewed — `agentstack add skill-willwebster5-agent-skills-cql-patterns`
  CQL pattern catalog — curated detection engineering patterns for CrowdStrike NG-SIEM. Use when writing, reviewing, or debugging CQL queries.
- [Fusion Workflows](https://agentstack.voostack.com/l/skill-willwebster5-agent-skills-fusion-workflows) — Skill · Free · security-reviewed — `agentstack add skill-willwebster5-agent-skills-fusion-workflows`
  >
- [Soc](https://agentstack.voostack.com/l/skill-willwebster5-agent-skills-soc) — Skill · Free · security-reviewed — `agentstack add skill-willwebster5-agent-skills-soc`
  Unified SOC analyst workflow for CrowdStrike NGSIEM — triage alerts, investigate security events, hunt threats, and tune detections. Use when triaging alerts, investigating detections, running daily SOC review, or tuning for false positives.
- [Behavioral Detections](https://agentstack.voostack.com/l/skill-willwebster5-agent-skills-behavioral-detections) — Skill · Free · security-reviewed — `agentstack add skill-willwebster5-agent-skills-behavioral-detections`
  Design multi-event behavioral detection rules using CrowdStrike NG-SIEM correlate() function. Use when building attack chain detections, correlating multiple events across time windows, or creating behavioral rules that detect complex threat patterns across AWS, EntraID, and CrowdStrike data sources.

---
Seller on AgentStack — the marketplace for AI agent skills and MCP servers. Every listing is security-reviewed. Install any with `agentstack add <slug>`.
