Performing Threat Hunting With Elastic Siem

Performs proactive threat hunting in Elastic Security SIEM using KQL/EQL queries, detection rules, and Timeline investigation to identify threats that evade automated detection. Use when SOC teams need to hunt for specific ATT&CK techniques, investigate anomalous behaviors, or validate detection coverage gaps using Elasticsearch and Kibana Security.

theheavenlyd3mon a1be302 4 files · 31.0 KB Updated 28 repo stars

File contents

theheavenlyd3mon/hermes-profiles/tree/main/profiles/cyber-blue-soc/skills/Anthropic-Cybersecurity-Skills/skills/performing-threat-hunting-with-elastic-siem commit a1be302c3a

Frequently asked questions

npx skillmds add theheavenlyd3mon/performing-threat-hunting-with-elastic-siem