SIEM Query Builder
Performance discipline: a correct query that does not return in reasonable time is operationally unusable. A lot of SOC time is lost in queries that scan unnecessarily much data. The second half of this skill is performance discipline, not just syntax.
When to use
This skill is the tooling substrate underneath detection-engineer (rules), log-triage (incident investigation), threat-hunt (proactive), and ioc-hunter (enrichment queries).
Triggers on:
- A q
[Description truncada. Veja o README completo no GitHub.]