Performing Threat Hunting With Elastic Siem

Use when performs proactive threat hunting in Elastic Security SIEM using KQL/EQL queries, detection rules, and Timeline investigation to identify threats that evade automated detection. Use when SOC teams need to hunt for specific ATT&CK techniques, investigate anomalous behaviors, or validate detection coverage gaps using Elasticsearch and Kibana Security.

oyi77 0f9302e 4.1 KB Updated 10 repo stars

File contents

oyi77/1ai-skills/tree/main/cybersecurity/performing-threat-hunting-with-elastic-siem commit 0f9302e815

Frequently asked questions

npx skillmds add oyi77/performing-threat-hunting-with-elastic-siem