community-automations/siem-alert-enrichment

DevOps y Código

PublicSubagente de Claude

Enriquecimiento de alertas SIEM

Los equipos de seguridad se ahogan en alertas del SIEM, la mayoría ruido que aun así cuesta minutos investigar a mano cada una. Esta automatización hace la primera ronda de investigación antes de que una persona la mire siquiera.

sonnet1 semanaSplunkVirusTotalAbuseIPDBMISP
ClaudeClaude
ROI for
README.md

Por qué este subagente

Los equipos de seguridad se ahogan en alertas del SIEM, la mayoría ruido que aun así cuesta minutos investigar a mano cada una. Esta automatización hace la primera ronda de investigación antes de que una persona la mire siquiera.

Enriquece cada indicador con threat intel, la propiedad del activo y los eventos relacionados, y luego puntúa la alerta. A los analistas solo se les avisa de las que importan, con las pruebas ya adjuntas, así el triaje arranca desde el contexto y no desde una pantalla en blanco.

Cómo se ejecuta

    • Read

      Used at step 01 to kick off the pipeline.

    • Write

      Used at step 01 to kick off the pipeline.

    • WebFetch

      Used at step 01 to kick off the pipeline.

    • WebSearch

      Used at step 01 to kick off the pipeline.

Salida de ejemplo

json
// Sample output
// (generated when the pipeline finishes)

Take a raw SIEM alert, enrich every indicator with threat-intel and asset context, then return a triage verdict (escalate or suppress) with a confidence score and the evidence behind it.

Unlock the rest

The full agent definition, install snippet, and starter task are gated for community members.

Members get the full `.md` agent file, the npm / pnpm install one-liners, a starter prompt that we've tuned against real runs, and the open-source repo when this automation ships there. One email, magic link, done.