보안 팀은 SIEM 알림에 파묻힙니다. 대부분 노이즈지만 하나하나 수동으로 조사하는 데 몇 분씩 걸리죠. 이 자동화는 사람이 확인하기 전에 1차 조사를 먼저 수행합니다.
sonnet1주 내 출시SplunkVirusTotalAbuseIPDBMISP
Claude
100ROI
81Scale
$3.4k92Saved
ROI for
README.md
왜 이 서브에이전트인가
보안 팀은 SIEM 알림에 파묻힙니다. 대부분 노이즈지만 하나하나 수동으로 조사하는 데 몇 분씩 걸리죠. 이 자동화는 사람이 확인하기 전에 1차 조사를 먼저 수행합니다.
모든 지표에 위협 인텔리전스, 자산 소유권, 관련 이벤트를 보강한 뒤 알림에 점수를 매깁니다. 분석가는 정말 중요한 항목에 대해서만 알림을 받으며, 증거가 이미 첨부되어 있어 빈 화면이 아닌 맥락에서부터 토리지를 시작할 수 있습니다.
작동 방식
Used at step 01 to kick off the pipeline.
Write
Used at step 01 to kick off the pipeline.
WebFetch
Used at step 01 to kick off the pipeline.
WebSearch
Used at step 01 to kick off the pipeline.
위반 지표(Indicator)를 위협 인텔리전스 피드와 평판 서비스에 대조해 알려진 악성 패턴과 매칭합니다.
pending
자산 소유자, 최근 로그인 이력 및 관련 알림을 추가해 분석가가 전체 상황을 파악할 수 있도록 합니다.
pending
보강된 알림에 점수를 부여하고, 신뢰도가 낮은 노이즈는 큐로 보낸 뒤 실제 위험이 있을 때만 인력을 호출합니다.
pending
샘플 출력
json
// Sample output
// (generated when the pipeline finishes)
Take a raw SIEM alert, enrich every indicator with threat-intel and asset context, then return a triage verdict (escalate or suppress) with a confidence score and the evidence behind it.
Unlock the rest
The full agent definition, install snippet, and starter task are gated for community members.
Members get the full `.md` agent file, the npm / pnpm install one-liners, a starter prompt that we've tuned against real runs, and the open-source repo when this automation ships there. One email, magic link, done.