Performing Threat Hunting With Elastic Siem

Performs proactive threat hunting in Elastic Security SIEM using KQL/EQL queries, detection rules, and Timeline investigation to identify threats that evade automated detection. Use when SOC teams need to hunt for specific ATT&CK techniques, investigate anomalous behaviors, or validate detection coverage gaps using Elasticsearch and Kibana Security.

gabrielmoreira Updated 17 repo stars

File contents

gabrielmoreira/agent-skills-mirror/tree/main/mirrors/repos/xalgord@xalgorix/internal/tools/skills/data/soc-operations/performing-threat-hunting-with-elastic-siem commit 7255caee96

Frequently asked questions

npx skillmds@latest add gabrielmoreira/performing-threat-hunting-with-elastic-siem