community-automations/siem-alert-enrichment

DevOps e Código

PublicSubagente Claude

Enriquecimento de Alertas SIEM

As equipas de segurança afogam-se em alertas SIEM, a maioria dos quais é ruído que ainda assim leva minutos a investigar manualmente. Esta automação faz a investigação inicial antes de qualquer humano analisar.

sonnet1 semanaSplunkVirusTotalAbuseIPDBMISP
ClaudeClaude
ROI for
README.md

Porquê este subagente

As equipas de segurança afogam-se em alertas SIEM, a maioria dos quais é ruído que ainda assim leva minutos a investigar manualmente. Esta automação faz a investigação inicial antes de qualquer humano analisar.

Enriquece cada indicador com inteligência de ameaças, propriedade de ativos e eventos relacionados, e depois pontua o alerta. Os analistas só são alertados para os que importam, com as evidências já anexadas, para que a triagem comece com contexto em vez de um ecrã vazio.

Como funciona

    • Read

      Used at step 01 to kick off the pipeline.

    • Write

      Used at step 01 to kick off the pipeline.

    • WebFetch

      Used at step 01 to kick off the pipeline.

    • WebSearch

      Used at step 01 to kick off the pipeline.

Saída de exemplo

json
// Sample output
// (generated when the pipeline finishes)

Take a raw SIEM alert, enrich every indicator with threat-intel and asset context, then return a triage verdict (escalate or suppress) with a confidence score and the evidence behind it.

Unlock the rest

The full agent definition, install snippet, and starter task are gated for community members.

Members get the full `.md` agent file, the npm / pnpm install one-liners, a starter prompt that we've tuned against real runs, and the open-source repo when this automation ships there. One email, magic link, done.