implementing-soar-playbook-for-phishing

mukul975/implementing-soar-playbook-for-phishing · Agent Skill (multi-file)

by mukul975 · bundle

Published · Last updated


Automate phishing incident response by creating Splunk SOAR containers, adding artifacts, and triggering investigation playbooks.

SKILL.md

Files

This skill is a package of 4 files. Install with the command above, or download the folder.

  • 📄SKILL.md entry
  • 📁references
  • 📄api-reference.md 2.5 KB
  • 📁scripts
  • ⚙️agent.py 8.6 KB
  • 📄LICENSE 11.0 KB

Related

  1. implementing-soar-automation-with-phantom · mukul975 bundle
    Automates alert triage, IOC enrichment, containment actions, and incident response playbooks using Splunk SOAR (Phantom) to reduce manual analyst work and standardize response procedures.
    24.6k
    repo stars
  2. implementing-soar-playbook-with-palo-alto-xsoar · mukul975 bundle
    Automate incident response workflows in Cortex XSOAR by building playbooks that orchestrate security tools, enrich indicators, and execute containment actions.
    24.6k
    repo stars
  3. building-incident-response-playbook · mukul975 bundle
    Designs and documents structured incident response playbooks aligned with NIST SP 800-61r3 and SANS PICERL frameworks, covering playbook structure, decision trees, escalation criteria, RACI matrices, and SOAR integration.
    24.6k
    repo stars
  4. conducting-phishing-incident-response · mukul975 bundle
    Responds to phishing incidents by analyzing reported emails, extracting indicators, assessing credential compromise, quarantining malicious messages, and remediating affected accounts.
    24.6k
    repo stars
  5. building-phishing-reporting-button-workflow · mukul975 bundle
    Deploy a phishing report button in email clients and build an automated triage workflow that analyzes user-reported suspicious emails, extracts IOCs, and provides feedback to reporters.
    24.6k
    repo stars
  6. building-soc-escalation-matrix · mukul975 bundle
    Build a structured SOC escalation matrix defining severity tiers, response SLAs, escalation paths, and notification procedures for security incidents.
    24.6k
    repo stars

Frequently asked questions

How do I install the implementing-soar-playbook-for-phishing skill?

Run npx skillmds add mukul975/implementing-soar-playbook-for-phishing in your terminal (requires Node.js), paste this page's agent-chat prompt into Claude, Cursor, or any MCP-connected agent, or download the SKILL.md file and copy it into your agent's skills directory.

What does the implementing-soar-playbook-for-phishing skill do?

Automate phishing incident response by creating Splunk SOAR containers, adding artifacts, and triggering investigation playbooks. It is listed under Security, Integrations & APIs, Incident Response, REST & GraphQL APIs on SkillMD.

Is implementing-soar-playbook-for-phishing safe to use?

SkillMD's automated safety review verdict for this skill is CAUTION. Independent scanners report: SkillSpector: PASS, Skill Scanner: PASS. Capability flags: executes scripts, reads secrets. SkillMD never runs a skill's scripts for you; review the SKILL.md before installing.

Which AI agents work with implementing-soar-playbook-for-phishing?

This skill is tagged as working with Claude Code, Claude.ai, OpenAI Codex. SKILL.md is an open format, so most agents that read a skills directory can load it too.

Is implementing-soar-playbook-for-phishing free to use?

Yes. Installing skills from SkillMD is free. This skill is licensed under Apache-2.

Who published implementing-soar-playbook-for-phishing?

mukul975 (@mukul975) published this skill. Their other Agent Skills are listed on their SkillMD profile.