community-automations/siem-alert-enrichment

DevOps & Κώδικας

PublicΥποπράκτορας Claude

Εμπλουτισμός ειδοποιήσεων SIEM

Οι ομάδες ασφαλείας πνίγονται στις ειδοποιήσεις SIEM, οι περισσότερες από τις οποίες είναι θόρυβος που και πάλι παίρνει λεπτά για να διερευνηθεί με το χέρι. Αυτή η αυτοματοποίηση κάνει την πρώτη έρευνα πριν καν ρίξει ματιά άνθρωπος.

sonnet1 εβδομάδαSplunkVirusTotalAbuseIPDBMISP
ClaudeClaude
ROI for
README.md

Γιατί αυτός ο subagent

Οι ομάδες ασφαλείας πνίγονται στις ειδοποιήσεις SIEM, οι περισσότερες από τις οποίες είναι θόρυβος που και πάλι παίρνει λεπτά για να διερευνηθεί με το χέρι. Αυτή η αυτοματοποίηση κάνει την πρώτη έρευνα πριν καν ρίξει ματιά άνθρωπος.

Εμπλουτίζει κάθε δείκτη με πληροφορίες απειλών, ιδιοκτησία asset και σχετικά συμβάντα, και μετά βαθμολογεί την ειδοποίηση. Οι αναλυτές ειδοποιούνται μόνο για αυτές που μετρούν, με τα αποδεικτικά ήδη συνημμένα, ώστε η διαλογή να ξεκινάει από πλαίσιο και όχι από μια κενή οθόνη.

Πώς λειτουργεί

    • Read

      Used at step 01 to kick off the pipeline.

    • Write

      Used at step 01 to kick off the pipeline.

    • WebFetch

      Used at step 01 to kick off the pipeline.

    • WebSearch

      Used at step 01 to kick off the pipeline.

Δείγμα εξόδου

json
// Sample output
// (generated when the pipeline finishes)

Take a raw SIEM alert, enrich every indicator with threat-intel and asset context, then return a triage verdict (escalate or suppress) with a confidence score and the evidence behind it.

Unlock the rest

The full agent definition, install snippet, and starter task are gated for community members.

Members get the full `.md` agent file, the npm / pnpm install one-liners, a starter prompt that we've tuned against real runs, and the open-source repo when this automation ships there. One email, magic link, done.