building-incident-response-dashboard

mukul975/building-incident-response-dashboard · Agent Skill (multi-file)

by mukul975 · bundle

Published · Last updated


Builds real-time incident response dashboards in Splunk, Elastic, or Grafana to provide SOC analysts and leadership with situational awareness during active incidents, tracking affected systems, containment status, IOC spread, and response timeline.

SKILL.md

Files

This skill is a package of 5 files. Install with the command above, or download the folder.

  • 📄SKILL.md entry
  • 📁references
  • 📄api-reference.md 2.2 KB
  • 📁scripts
  • ⚙️agent.py 7.2 KB
  • 📄LICENSE 11.0 KB
  • 📄SKILL.es.md 12.2 KB

Related

  1. building-soc-playbook-for-ransomware · mukul975 bundle
    Builds a structured SOC incident response playbook for ransomware attacks covering detection, containment, eradication, and recovery phases with specific SIEM queries, isolation procedures, and decision trees.
    24.6k
    repo stars
  2. implementing-alert-fatigue-reduction · mukul975 bundle
    Reduces SOC alert fatigue by tuning detection rules, consolidating duplicate alerts, implementing risk-based alerting, and measuring alert quality metrics to maintain analyst effectiveness.
    24.6k
    repo stars
  3. building-soc-metrics-and-kpi-tracking · mukul975 bundle
    Builds SOC performance metrics and KPI tracking dashboards measuring Mean Time to Detect (MTTD), Mean Time to Respond (MTTR), alert quality ratios, analyst productivity, and detection coverage using SIEM data.
    24.6k
    repo stars
  4. triaging-security-incident · mukul975 bundle
    Triages security incidents by classifying type, assigning severity based on business impact, enriching with threat intelligence, and routing to appropriate response teams using NIST SP 800-61r3 and SANS PICERL frameworks.
    24.6k
    repo stars
  5. detecting-service-account-abuse · mukul975 bundle
    Detect abuse of service accounts through anomalous interactive logons, privilege escalation, lateral movement, and unauthorized access patterns.
    24.6k
    repo stars
  6. implementing-siem-use-cases-for-detection · mukul975 bundle
    Design, implement, test, and maintain SIEM detection rules mapped to MITRE ATT&CK across Splunk, Elastic, and Sentinel platforms.
    24.6k
    repo stars

Frequently asked questions

How do I install the building-incident-response-dashboard skill?

Run npx skillmds add mukul975/building-incident-response-dashboard in your terminal (requires Node.js), paste this page's agent-chat prompt into Claude, Cursor, or any MCP-connected agent, or download the SKILL.md file and copy it into your agent's skills directory.

What does the building-incident-response-dashboard skill do?

Builds real-time incident response dashboards in Splunk, Elastic, or Grafana to provide SOC analysts and leadership with situational awareness during active incidents, tracking affected systems, containment status, IOC spread, and response timeline. It is listed under Security, Coding & Dev Tools, Data & Analytics, Data Visualization, Incident Response on SkillMD.

Is building-incident-response-dashboard safe to use?

SkillMD's automated safety review verdict for this skill is CAUTION. Independent scanners report: SkillSpector: PASS, Skill Scanner: PASS. Capability flags: executes scripts. SkillMD never runs a skill's scripts for you; review the SKILL.md before installing.

Which AI agents work with building-incident-response-dashboard?

This skill is tagged as working with Claude Code, Claude.ai, OpenAI Codex. SKILL.md is an open format, so most agents that read a skills directory can load it too.

Is building-incident-response-dashboard free to use?

Yes. Installing skills from SkillMD is free. This skill is licensed under Apache-2.

Who published building-incident-response-dashboard?

mukul975 (@mukul975) published this skill. Their other Agent Skills are listed on their SkillMD profile.