implementing-soar-automation-with-phantom

mukul975/implementing-soar-automation-with-phantom · Agent Skill (multi-file)

by mukul975 · bundle

Published · Last updated


Automates alert triage, IOC enrichment, containment actions, and incident response playbooks using Splunk SOAR (Phantom) to reduce manual analyst work and standardize response procedures.

SKILL.md

Files

This skill is a package of 4 files. Install with the command above, or download the folder.

  • 📄SKILL.md entry
  • 📁references
  • 📄api-reference.md 2.6 KB
  • 📁scripts
  • ⚙️agent.py 9.4 KB
  • 📄LICENSE 11.0 KB

Related

  1. implementing-soar-playbook-for-phishing · mukul975 bundle
    Automate phishing incident response by creating Splunk SOAR containers, adding artifacts, and triggering investigation playbooks.
    24.6k
    repo stars
  2. automating-ioc-enrichment · mukul975 bundle
    Automates enrichment of raw indicators of compromise with multi-source threat intelligence context using SOAR platforms, Python pipelines, or TIP playbooks to reduce analyst triage time and standardize enrichment outputs.
    24.6k
    repo stars
  3. building-incident-response-playbook · mukul975 bundle
    Designs and documents structured incident response playbooks aligned with NIST SP 800-61r3 and SANS PICERL frameworks, covering playbook structure, decision trees, escalation criteria, RACI matrices, and SOAR integration.
    24.6k
    repo stars
  4. implementing-soar-playbook-with-palo-alto-xsoar · mukul975 bundle
    Automate incident response workflows in Cortex XSOAR by building playbooks that orchestrate security tools, enrich indicators, and execute containment actions.
    24.6k
    repo stars
  5. building-soc-escalation-matrix · mukul975 bundle
    Build a structured SOC escalation matrix defining severity tiers, response SLAs, escalation paths, and notification procedures for security incidents.
    24.6k
    repo stars
  6. conducting-malware-incident-response · mukul975 bundle
    Responds to malware infections across enterprise endpoints by identifying the malware family, determining infection vectors, assessing spread, and executing eradication procedures.
    24.6k
    repo stars

Frequently asked questions

How do I install the implementing-soar-automation-with-phantom skill?

Run npx skillmds add mukul975/implementing-soar-automation-with-phantom in your terminal (requires Node.js), paste this page's agent-chat prompt into Claude, Cursor, or any MCP-connected agent, or download the SKILL.md file and copy it into your agent's skills directory.

What does the implementing-soar-automation-with-phantom skill do?

Automates alert triage, IOC enrichment, containment actions, and incident response playbooks using Splunk SOAR (Phantom) to reduce manual analyst work and standardize response procedures. It is listed under Security, Incident Response on SkillMD.

Is implementing-soar-automation-with-phantom safe to use?

SkillMD's automated safety review verdict for this skill is CAUTION. Independent scanners report: SkillSpector: PASS, Skill Scanner: PASS. Capability flags: executes scripts, makes network calls, reads secrets. SkillMD never runs a skill's scripts for you; review the SKILL.md before installing.

Which AI agents work with implementing-soar-automation-with-phantom?

This skill is tagged as working with Claude Code, Claude.ai, OpenAI Codex. SKILL.md is an open format, so most agents that read a skills directory can load it too.

Is implementing-soar-automation-with-phantom free to use?

Yes. Installing skills from SkillMD is free. This skill is licensed under Apache-2.

Who published implementing-soar-automation-with-phantom?

mukul975 (@mukul975) published this skill. Their other Agent Skills are listed on their SkillMD profile.