community-automations/siem-alert-enrichment

DevOps & code

PublicClaude-subagent

SIEM-alert-verrijking

Securityteams verzuipen in SIEM-alerts, waarvan de meeste ruis zijn die toch elk minuten kosten om met de hand uit te zoeken. Deze automatisering doet het eerste onderzoek voordat een mens er ook maar naar kijkt.

sonnet1 weekSplunkVirusTotalAbuseIPDBMISP
ClaudeClaude
ROI for
README.md

Waarom deze subagent

Securityteams verzuipen in SIEM-alerts, waarvan de meeste ruis zijn die toch elk minuten kosten om met de hand uit te zoeken. Deze automatisering doet het eerste onderzoek voordat een mens er ook maar naar kijkt.

Het verrijkt elke indicator met threat intel, asset-eigenaarschap en gerelateerde gebeurtenissen, en scoort vervolgens het alert. Analisten worden alleen gepaged voor de alerts die ertoe doen, met het bewijs er al bij, zodat triage begint vanuit context in plaats van een leeg scherm.

Hoe hij werkt

    • Read

      Used at step 01 to kick off the pipeline.

    • Write

      Used at step 01 to kick off the pipeline.

    • WebFetch

      Used at step 01 to kick off the pipeline.

    • WebSearch

      Used at step 01 to kick off the pipeline.

Voorbeelduitvoer

json
// Sample output
// (generated when the pipeline finishes)

Take a raw SIEM alert, enrich every indicator with threat-intel and asset context, then return a triage verdict (escalate or suppress) with a confidence score and the evidence behind it.

Unlock the rest

The full agent definition, install snippet, and starter task are gated for community members.

Members get the full `.md` agent file, the npm / pnpm install one-liners, a starter prompt that we've tuned against real runs, and the open-source repo when this automation ships there. One email, magic link, done.