community-automations/siem-alert-enrichment

DevOps&コード

PublicClaude サブエージェント

SIEMアラート拡張

セキュリティチームはSIEMアラートに埋もれている。その大半はノイズだが、それでも1件ずつ手作業で調査すれば数分かかる。このオートメーションは、人が目を通す前に一次調査を済ませる。

sonnet1週間SplunkVirusTotalAbuseIPDBMISP
ClaudeClaude
ROI for
README.md

このサブエージェントを選ぶ理由

セキュリティチームはSIEMアラートに埋もれている。その大半はノイズだが、それでも1件ずつ手作業で調査すれば数分かかる。このオートメーションは、人が目を通す前に一次調査を済ませる。

すべてのインジケーターに脅威インテリジェンス、資産の所有者、関連イベントを付加し、アラートをスコアリングする。アナリストにページが届くのは本当に重要なものだけ。証拠もすでに添付されており、トリアージは白紙の画面ではなく文脈を持った状態から始まる。

動作の流れ

    • Read

      Used at step 01 to kick off the pipeline.

    • Write

      Used at step 01 to kick off the pipeline.

    • WebFetch

      Used at step 01 to kick off the pipeline.

    • WebSearch

      Used at step 01 to kick off the pipeline.

出力サンプル

json
// Sample output
// (generated when the pipeline finishes)

Take a raw SIEM alert, enrich every indicator with threat-intel and asset context, then return a triage verdict (escalate or suppress) with a confidence score and the evidence behind it.

Unlock the rest

The full agent definition, install snippet, and starter task are gated for community members.

Members get the full `.md` agent file, the npm / pnpm install one-liners, a starter prompt that we've tuned against real runs, and the open-source repo when this automation ships there. One email, magic link, done.