community-automations/siem-alert-enrichment

DevOps 與程式碼

PublicClaude 子代理

SIEM 警報自動豐富化

資安團隊總是被 SIEM 警報淹沒,其中大多數是噪音,卻每一則都得花上幾分鐘手動調查。這套自動化會在人類接手之前,先完成第一輪的情資蒐集。

sonnet1 週SplunkVirusTotalAbuseIPDBMISP
ClaudeClaude
ROI for
README.md

為什麼選擇此子代理

資安團隊總是被 SIEM 警報淹沒,其中大多數是噪音,卻每一則都得花上幾分鐘手動調查。這套自動化會在人類接手之前,先完成第一輪的情資蒐集。

它會為每一個指標補上威脅情資、資產歸屬與相關事件,再為警報評分。分析師只會被那些真正重要的警報呼叫,而且證據早已附上,讓分流作業從完整的脈絡開始,而不是面對一片空白。

運作方式

    • Read

      Used at step 01 to kick off the pipeline.

    • Write

      Used at step 01 to kick off the pipeline.

    • WebFetch

      Used at step 01 to kick off the pipeline.

    • WebSearch

      Used at step 01 to kick off the pipeline.

輸出範例

json
// Sample output
// (generated when the pipeline finishes)

Take a raw SIEM alert, enrich every indicator with threat-intel and asset context, then return a triage verdict (escalate or suppress) with a confidence score and the evidence behind it.

Unlock the rest

The full agent definition, install snippet, and starter task are gated for community members.

Members get the full `.md` agent file, the npm / pnpm install one-liners, a starter prompt that we've tuned against real runs, and the open-source repo when this automation ships there. One email, magic link, done.