correlating-security-events-in-qradar

mukul975/correlating-security-events-in-qradar · Agent Skill (multi-file)

by mukul975 · bundle

Published · Last updated


Correlates security events in IBM QRadar SIEM using AQL queries, custom rules, building blocks, and offense management to detect multi-stage attacks across network, endpoint, and application log sources.

SKILL.md

Files

This skill is a package of 4 files. Install with the command above, or download the folder.

  • 📄SKILL.md entry
  • 📁references
  • 📄api-reference.md 2.2 KB
  • 📁scripts
  • ⚙️agent.py 6.5 KB
  • 📄LICENSE 11.0 KB

Related

  1. implementing-siem-use-cases-for-detection · mukul975 bundle
    Design, implement, test, and maintain SIEM detection rules mapped to MITRE ATT&CK across Splunk, Elastic, and Sentinel platforms.
    24.6k
    repo stars
  2. detection-engineering-coverage-evaluation · google
    Automates detection engineering workflows in Google SecOps by extracting threat intelligence, generating detection opportunities, simulating attacker behavior with synthetic events, evaluating rule coverage, and creating new YARA-L 2.0 rules to close gaps.
    14.4k
    repo stars
  3. implementing-siem-correlation-rules-for-apt · mukul975 bundle
    Detect APT lateral movement by chaining Windows authentication events, process execution telemetry, and network connection logs across hosts using Splunk SPL and Sigma rule format.
    24.6k
    repo stars
  4. threat-hunting · zhaoxuya520 bundle
    Guides blue-team threat hunting and detection engineering with hypothesis-driven workflows, Sigma/YARA rule creation, SIEM query design, and validation using Atomic Red Team in authorized environments.
    12.8k
    repo stars
  5. detecting-service-account-abuse · mukul975 bundle
    Detect abuse of service accounts through anomalous interactive logons, privilege escalation, lateral movement, and unauthorized access patterns.
    24.6k
    repo stars
  6. detecting-business-email-compromise · mukul975 bundle
    Detect business email compromise (BEC) attacks using email gateway rules, behavioral analytics, and financial process controls.
    24.6k
    repo stars

Frequently asked questions

How do I install the correlating-security-events-in-qradar skill?

Run npx skillmds add mukul975/correlating-security-events-in-qradar in your terminal (requires Node.js), paste this page's agent-chat prompt into Claude, Cursor, or any MCP-connected agent, or download the SKILL.md file and copy it into your agent's skills directory.

What does the correlating-security-events-in-qradar skill do?

Correlates security events in IBM QRadar SIEM using AQL queries, custom rules, building blocks, and offense management to detect multi-stage attacks across network, endpoint, and application log sources. It is listed under Security, Incident Response on SkillMD.

Is correlating-security-events-in-qradar safe to use?

SkillMD's automated safety review verdict for this skill is CAUTION. Independent scanners report: SkillSpector: PASS, Skill Scanner: PASS. Capability flags: executes scripts, makes network calls. SkillMD never runs a skill's scripts for you; review the SKILL.md before installing.

Which AI agents work with correlating-security-events-in-qradar?

This skill is tagged as working with Claude Code, Claude.ai, OpenAI Codex. SKILL.md is an open format, so most agents that read a skills directory can load it too.

Is correlating-security-events-in-qradar free to use?

Yes. Installing skills from SkillMD is free. This skill is licensed under Apache-2.

Who published correlating-security-events-in-qradar?

mukul975 (@mukul975) published this skill. Their other Agent Skills are listed on their SkillMD profile.