community-automations/siem-alert-enrichment

DevOps ve Kod

PublicClaude otomasyonu

SIEM Alarm Zenginleştirme

Güvenlik ekipleri SIEM uyarılarında boğulur; çoğu gürültüdür ama yine de her biri elle araştırıldığında dakikalar yer. Bu otomasyon, bir insan daha bakmadan ilk tur araştırmayı yapar.

sonnet1 haftaSplunkVirusTotalAbuseIPDBMISP
ClaudeClaude
ROI for
README.md

Bu otomasyon neden işinize yarar

Güvenlik ekipleri SIEM uyarılarında boğulur; çoğu gürültüdür ama yine de her biri elle araştırıldığında dakikalar yer. Bu otomasyon, bir insan daha bakmadan ilk tur araştırmayı yapar.

Her göstergeyi tehdit istihbaratı, varlık sahipliği ve ilgili olaylarla zenginleştirir, sonra uyarıyı puanlar. Analistler yalnızca önemli olanlar için çağrılır, hem de kanıt çoktan iliştirilmiş halde; böylece triyaj boş bir ekran yerine bağlamdan başlar.

Nasıl çalışır

    • Read

      Used at step 01 to kick off the pipeline.

    • Write

      Used at step 01 to kick off the pipeline.

    • WebFetch

      Used at step 01 to kick off the pipeline.

    • WebSearch

      Used at step 01 to kick off the pipeline.

Örnek çıktı

json
// Sample output
// (generated when the pipeline finishes)

Take a raw SIEM alert, enrich every indicator with threat-intel and asset context, then return a triage verdict (escalate or suppress) with a confidence score and the evidence behind it.

Unlock the rest

The full agent definition, install snippet, and starter task are gated for community members.

Members get the full `.md` agent file, the npm / pnpm install one-liners, a starter prompt that we've tuned against real runs, and the open-source repo when this automation ships there. One email, magic link, done.