Siem Query Authoring

Turn an investigative question, a hunt hypothesis, or an indicator list into a correct, efficient query for the team's SIEM: Microsoft Sentinel / Defender XDR (KQL), Splunk (SPL with CIM), Elastic (KQL, EQL, ES|QL over ECS), Google SecOps / Chronicle (UDM search, YARA-L), or Athena / BigQuery SQL over CloudTrail, VPC flow and audit logs. Use it whenever someone asks to "write a query", "search the SIEM for", "check if any host talked to", "find logons from", "translate this SPL to KQL", "why does my query return nothing / time out", or hands over an IOC list (typically the CSV from `ioc-extraction`) that needs to become a retro-hunt. Also use it when another skill needs a query run: backtests for `detection-engineering`, hunt queries for `threat-hunting`, scoping for `incident-triage`.

ftrout Updated

File contents

ftrout/secops-claude-skills/tree/main/skills/siem-query-authoring commit 66e34c3953

Frequently asked questions

npx skillmds@latest add ftrout/siem-query-authoring