Siem Rules

Guides development of SIEM detection rules using KQL (Microsoft Sentinel) and SPL (Splunk) query languages, mapped to MITRE ATT&CK v16 techniques. Auto-invoked when the user needs to write SIEM queries, tune alert thresholds, build correlation rules, or manage the detection rule lifecycle. Produces production-ready queries with detection logic patterns, threshold tuning guidance, and lifecycle management.

sugatoray 393b3c2 29.3 KB Updated

File contents

sugatoray/unitoneai-securityskills/tree/main/skills/secops/siem-rules commit 393b3c2d63

Frequently asked questions

npx skillmds@latest add sugatoray/siem-rules