Skills DirectorySkills Directory
SkillsLearnSecurityCategoriesDocsBlogPro
Sign InSubmit Skill
Skills Directory

Security-tested agent skills for Claude, coding agents, and AI workflows.

Directory

  • Browse Skills
  • All Skills A–Z
  • Claude Skills
  • Claude Code Skills
  • Agent Skills
  • Categories
  • Authors
  • Submit a Skill

Learn

  • Learn Hub
  • Install Claude Skills
  • Write SKILL.md
  • Skills vs MCP
  • Directories Compared

Security

  • Security
  • Methodology
  • Secure Claude Skills
  • Security Badges
  • Chrome Extension
  • Skill Manager

Company

  • About
  • Community
  • Blog
  • API Docs
  • Advertise

2026 Skills Directory. All rights reserved.

ProTermsPrivacyRefunds
Back to skills

Siem

ASecurity

Routing agent for SIEM & SOAR technologies. Cross-platform expertise in log management, event correlation, detection engineering, normalization, SIGMA rules, and security orchestration. WHEN: \"SIEM comparison\", \"which SIEM\", \"log management\", \"detection engineering\", \"SIGMA rules\", \"security analytics\", \"correlation rules\", \"SOAR platform\", \"security automation\", \"alert triage\". Do NOT use for platform-specific questions -- use the `splunk`, `sentinel`, `elastic-security`,...

4 stars
0 votes
0 copies
0 views
Added 9/24/2026
datagoshellsqlnodeawsgcpazuretestingsecurityperformance

Works with

cli

Security Analysis

A100/100

Pro scans all 2 files and shows the line behind each finding

Scanned 9/24/2026

$npx -y skills add chrishuffman5/domain-expert --skill siem --agent claude-code

Installs into .claude/skills of the current project.

Are you the author of Siem?

Add the live security badge to your README — it updates automatically with every re-scan.

Security grade badge for Siem
[![Security: A — Skills Directory](https://www.skillsdirectory.com/api/skills/chrishuffman5-siem/badge)](https://www.skillsdirectory.com/skills/chrishuffman5-siem)

More formats (shields.io, HTML) on the badges page. Keep it an A: scan every change in CI with Pro.

Download with Pro
Files
SKILL.md
---
name: siem
description: "Routing agent for SIEM & SOAR technologies. Cross-platform expertise in log management, event correlation, detection engineering, normalization, SIGMA rules, and security orchestration. WHEN: \"SIEM comparison\", \"which SIEM\", \"log management\", \"detection engineering\", \"SIGMA rules\", \"security analytics\", \"correlation rules\", \"SOAR platform\", \"security automation\", \"alert triage\". Do NOT use for platform-specific questions -- use the `splunk`, `sentinel`, `elastic-security`, `qradar`, `chronicle`, `xsiam`, `splunk-es`, or `soar` skill."
license: MIT
---

# SIEM & SOAR

This skill covers all SIEM (Security Information and Event Management) and SOAR (Security Orchestration, Automation, and Response) technologies. It provides cross-platform expertise in log management, event correlation, detection engineering, normalization standards, and security automation. Read the relevant sibling skill for deep implementation details.

## When to Use This Skill vs. a Sibling Skill

**Use this skill when the question is cross-platform or conceptual:**
- "Which SIEM should we choose for our environment?"
- "How do we build a detection engineering program?"
- "Compare Splunk vs. Sentinel vs. Elastic for our use case"
- "What is the best normalization standard?"
- "How do SIGMA rules work across platforms?"
- "Design our SOC architecture"
- "SIEM data onboarding strategy"
- "How much log storage do we need?"
- "SOAR vs. SIEM automation -- where do we draw the line?"

**Read a sibling skill when the question is platform-specific:**
- "Write an SPL correlation search" --> `splunk`
- "Splunk Enterprise Security risk-based alerting" --> `splunk-es`
- "KQL query for Sentinel analytics rule" --> `sentinel`
- "Elastic EQL sequence detection" --> `elastic-security`
- "QRadar AQL offense query" --> `qradar`
- "Chronicle YARA-L detection rule" --> `chronicle`
- "XSIAM XQL correlation" --> `xsiam`
- "LogScale LQL streaming query" --> `logscale`
- "Build an XSOAR playbook" --> `xsoar`
- "Splunk SOAR automation" --> `splunk-soar`
- "Sentinel playbook with Logic Apps" --> `sentinel-playbooks`

## How to Approach Tasks

When you receive a request:

1. **Classify** the request:
   - **Platform selection** -- Compare SIEM/SOAR platforms against requirements
   - **Architecture / Strategy** -- Load `references/concepts.md` for foundational SIEM concepts
   - **Detection engineering** -- Cross-platform detection methodology, SIGMA rules, MITRE ATT&CK mapping
   - **Data onboarding** -- Log source strategy, normalization, parsing, enrichment
   - **SOC operations** -- Triage workflows, alert management, metrics (MTTD, MTTR)
   - **Cost optimization** -- Ingestion volume, tiering, filtering, retention policies
   - **Platform-specific** -- Read the appropriate sibling skill

2. **Gather context** -- Environment (cloud/on-prem/hybrid), team size, budget, existing tooling, compliance requirements, log volume (GB/day), retention needs

3. **Analyze** -- Apply SIEM-specific reasoning. Consider data volume, query performance, detection coverage, operational maturity, and total cost of ownership.

4. **Recommend** -- Provide prioritized recommendations with trade-offs. SIEM selection is never one-size-fits-all.

5. **Qualify** -- State assumptions about scale, team skill, and budget constraints

## SIEM Fundamentals

### Core SIEM Functions

1. **Log Collection** -- Aggregate logs from endpoints, network devices, cloud services, applications, and identity providers
2. **Normalization** -- Transform raw logs into a consistent schema (CIM, ECS, ASIM, UDM) for cross-source correlation
3. **Indexing / Storage** -- Store normalized events for real-time and historical search
4. **Correlation** -- Match patterns across multiple log sources to detect threats (correlation rules, analytics rules)
5. **Alerting** -- Generate alerts when correlation rules trigger, with severity and context
6. **Investigation** -- Provide search, drill-down, and visualization for analyst triage
7. **Reporting** -- Compliance reporting, SOC metrics, executive dashboards

### Detection Engineering Lifecycle

```
1. Threat Intelligence    -->  What threats target our environment?
        |
2. Data Source Mapping    -->  Do we have visibility? (MITRE ATT&CK data sources)
        |
3. Detection Logic        -->  Write detection rules (platform-native or SIGMA)
        |
4. Testing & Validation   -->  Atomic Red Team, Caldera, manual simulation
        |
5. Tuning                 -->  Reduce false positives, add exceptions, refine thresholds
        |
6. Deployment             -->  Promote to production with severity and response actions
        |
7. Metrics & Maintenance  -->  Track detection coverage, MTTD, alert fidelity, rule decay
```

### SIGMA Rules

SIGMA is a vendor-agnostic detection rule format that compiles to platform-specific queries:

```yaml
title: Suspicious PowerShell Download Cradle
id: 3b6ab547-8ec2-4991-b9d2-2b06702a48d7
status: stable
description: Detects PowerShell download cradles commonly used by attackers
logsource:
    category: process_creation
    product: windows
detection:
    selection:
        CommandLine|contains|all:
            - 'powershell'
            - 'Net.WebClient'
        CommandLine|contains:
            - 'DownloadString'
            - 'DownloadFile'
    condition: selection
level: high
tags:
    - attack.execution
    - attack.t1059.001
```

SIGMA compiles to:
- **Splunk SPL**: `index=windows sourcetype=WinEventLog:Security ... | search CommandLine="*powershell*Net.WebClient*DownloadString*"`
- **Sentinel KQL**: `SecurityEvent | where CommandLine has_all ("powershell", "Net.WebClient") and CommandLine has_any ("DownloadString", "DownloadFile")`
- **Elastic EQL**: Process creation event with matching command line patterns
- **QRadar AQL**: SQL-like query against normalized fields
- **Chronicle YARA-L**: Event match with target.process.command_line conditions

### Normalization Standards

| Standard | Platform | Key Concept |
|---|---|---|
| **CIM** (Common Information Model) | Splunk | Data models with standardized field names; acceleration for dashboards |
| **ECS** (Elastic Common Schema) | Elastic | Hierarchical field naming (e.g., `process.name`, `source.ip`) |
| **ASIM** (Advanced Security Information Model) | Sentinel | Unifying parsers that normalize at query time; schema-based |
| **UDM** (Unified Data Model) | Chronicle | Google's schema for security telemetry; entity-centric |
| **OCSF** (Open Cybersecurity Schema Framework) | Cross-platform | AWS-originated open standard; growing adoption |

### Data Onboarding Strategy

Prioritize log sources by detection value:

| Priority | Log Sources | Detection Value |
|---|---|---|
| **P1 -- Critical** | EDR, identity (AD/Entra), email gateway, firewall/proxy | Core visibility for 80% of attack techniques |
| **P2 -- High** | Cloud audit logs (AWS CloudTrail, Azure Activity, GCP Audit), DNS, DHCP | Lateral movement, cloud compromise, C2 detection |
| **P3 -- Medium** | Application logs, VPN, DLP, vulnerability scanners | Insider threat, data exfiltration, vulnerability correlation |
| **P4 -- Low** | Network flow (NetFlow/IPFIX), PCAP metadata, printer logs | Forensic enrichment, compliance, niche detections |

### Alert Triage Framework

Effective triage reduces Mean Time to Detect (MTTD) and Mean Time to Respond (MTTR):

1. **Tier 0 -- Automated** -- SOAR handles enrichment, deduplication, known-false-positive suppression, auto-close of informational alerts
2. **Tier 1 -- Triage** -- Analyst validates alert, checks context (asset criticality, user risk score, related alerts), escalates or closes
3. **Tier 2 -- Investigation** -- Deep-dive analysis, timeline reconstruction, scope assessment, containment decisions
4. **Tier 3 -- Hunt** -- Proactive hypothesis-driven threat hunting using SIEM search and detection gaps

## SIEM Platform Comparison

| Capability | Splunk | Sentinel | Elastic Security | QRadar | Chronicle | XSIAM | LogScale |
|---|---|---|---|---|---|---|---|
| **Query Language** | SPL / SPL2 | KQL | EQL, ES\|QL, KQL, Lucene | AQL (SQL-like) | YARA-L 2.0 | XQL | LQL |
| **Normalization** | CIM | ASIM | ECS | QID + DSM | UDM | XDM | Custom | 
| **Deployment** | On-prem, Cloud, Hybrid | Cloud-native (Azure) | On-prem, Cloud, Hybrid | On-prem (SaaS divested) | Cloud-native (GCP) | Cloud-native | Cloud, Self-hosted |
| **Pricing Model** | Ingestion (GB/day) or workload | Ingestion (GB/day) + retention | Node-based or ingestion | EPS (events/sec) | Flat (per user) | Ingestion + compute | Ingestion (GB/day) |
| **SOAR Built-in** | Via Splunk SOAR (separate) | Playbooks (Logic Apps) | Response actions (limited) | QRadar SOAR (separate) | SOAR module | Automation Center | Via Falcon Fusion |
| **ML / AI** | MLTK, predictive analytics | Fusion ML, UEBA, Copilot | ML anomaly detection jobs | Anomaly detection | Duet AI, Mandiant TI | XSIAM Copilot, ML clustering | Statistical functions |
| **Strengths** | Mature ecosystem, SPL power, Splunkbase | Azure integration, cost tiers, Defender XDR | Open source core, EQL sequences, flexible | Automatic offense grouping, AQL familiarity | Unlimited retention, retroactive rules, Mandiant TI | Converged platform (SIEM+SOAR+XDR), AI-first | High-volume streaming, index-free, real-time |
| **Weaknesses** | Cost at scale, complexity | Azure-centric, KQL learning curve | Operational overhead (self-managed), complexity | Aging platform, SaaS discontinued | GCP-centric, limited customization | Vendor lock-in, emerging maturity | Smaller ecosystem, limited SOAR |

### Platform Selection Decision Tree

```
Start: What is your primary cloud?
  |
  ├── Azure-heavy  -->  Microsoft Sentinel (native integration with Defender XDR, Entra, M365)
  |
  ├── GCP-heavy    -->  Chronicle/Google SecOps (native GCP integration, Mandiant TI)
  |
  ├── AWS-heavy    -->  Consider Splunk Cloud, Elastic, or XSIAM (no dominant AWS-native SIEM)
  |
  └── Multi-cloud / On-prem
       |
       ├── Budget priority         -->  Elastic Security (open source core) or LogScale (competitive pricing)
       ├── Mature SOC, complex needs -->  Splunk (deepest ecosystem, SPL power)
       ├── Converged SOC platform   -->  XSIAM (SIEM + SOAR + XDR in one)
       └── High-volume, real-time   -->  LogScale (streaming architecture, index-free)
```

## SOC Metrics

Track these metrics to measure SIEM/SOAR effectiveness:

| Metric | Definition | Target |
|---|---|---|
| **MTTD** | Mean Time to Detect -- time from event to alert | < 1 hour for critical threats |
| **MTTR** | Mean Time to Respond -- time from alert to containment | < 4 hours for critical incidents |
| **Alert Fidelity** | True positives / total alerts | > 80% (below 50% = alert fatigue) |
| **Detection Coverage** | ATT&CK techniques with active detections / total relevant techniques | > 60% for top tactics |
| **Automation Rate** | Alerts handled by SOAR without human intervention | > 40% for mature SOCs |
| **Dwell Time** | Attacker presence before detection | Reduce quarter over quarter |
| **EPS / GB per Day** | Ingestion volume | Monitor for budget forecasting |

## Cost Optimization Strategies

SIEM costs are driven primarily by ingestion volume. Common optimization tactics:

1. **Tiered storage** -- Use hot/warm/cold/frozen tiers. Not all data needs fast search (Splunk SmartStore, Sentinel basic logs, Elastic frozen tier).
2. **Filtering at source** -- Drop noisy, low-value events before ingestion (verbose debug logs, health checks, success-only auth events).
3. **Summary indexing** -- Pre-aggregate statistics for reporting; keep raw data shorter.
4. **Log routing** -- Send compliance-only logs to cheap storage (S3, blob); send security-relevant logs to SIEM.
5. **Data model acceleration** -- Pre-compute common searches to avoid expensive full-index scans.
6. **Commitment tiers** -- Most vendors offer discounts for committed ingestion volumes (Sentinel commitment tiers, Splunk workload pricing).
7. **Event sampling** -- For extremely high-volume, low-fidelity sources (e.g., NetFlow), sample instead of ingesting 100%.

## Anti-Patterns to Watch For

1. **"Collect everything, detect later"** -- Ingesting every log without a detection plan leads to massive costs and no security value. Map data sources to specific detections.
2. **"One alert per threat"** -- Single-event detections produce noise. Use correlation (multi-event, multi-source) and risk-based scoring.
3. **"SIEM as a log archive"** -- A SIEM without active detection rules is an expensive log store. Invest in detection engineering.
4. **"Copy-paste vendor rules"** -- Default rules without tuning generate alert fatigue. Every rule needs environment-specific tuning.
5. **"Ignoring the data pipeline"** -- Normalization, parsing, and enrichment quality determine detection quality. Garbage in, garbage out.
6. **"SOAR without mature processes"** -- Automating bad processes makes them faster, not better. Define playbooks manually before automating.
7. **"Single-platform lock-in"** -- Over-reliance on one vendor's ecosystem makes migration painful. Use SIGMA for portable detections where possible.

## Technology Routing

Read these sibling skills for platform-specific expertise:

| Request Pattern | Route To |
|---|---|
| **SIEM Platforms** | |
| Splunk, SPL, search heads, indexers, forwarders, SmartStore | `splunk` (see its Version-Specific Guidance) |
| Splunk Enterprise Security, ES, notable events, RBA | `splunk-es` |
| Microsoft Sentinel, KQL, ASIM, Fusion, analytics rules | `sentinel` |
| Elastic Security, EQL, ES\|QL, detection engine, Fleet | `elastic-security` (see its Version-Specific Guidance) |
| IBM QRadar, AQL, offenses, DSMs, Ariel | `qradar` |
| Google Chronicle, YARA-L, UDM, SecOps | `chronicle` |
| Palo Alto XSIAM, XQL, AI-driven SOC | `xsiam` |
| CrowdStrike LogScale, LQL, streaming SIEM | `logscale` |
| **SOAR Platforms** | |
| SOAR platform comparison, playbook strategy | `soar` |
| Cortex XSOAR, playbook IDE, war rooms | `xsoar` |
| Splunk SOAR, Phantom, visual playbooks | `splunk-soar` |
| Sentinel Playbooks, Logic Apps automation | `sentinel-playbooks` |
| Tines, no-code security automation | `tines` |
| Torq, hyperautomation, SOC copilot | `torq` |

## Reference Files

Load these for deep foundational knowledge:

- `references/concepts.md` -- SIEM/SOAR foundational concepts: log management lifecycle, event correlation theory, normalization standards, SIGMA rule language, detection engineering methodology, SOC maturity model. Read for "how does SIEM work" or cross-platform architecture questions.

Attribution

chrishuffman5chrishuffman5
View sourceSee grades on GitHubMore from chrishuffman5 →
SSkills DirectorySkills Directory

Ship a skill? Prove it's safe.

Free 120-pattern security scan, letter grade, and an embeddable README badge.

Submit a skill

Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.

Comments (0)

No comments yet. Be the first to comment!

SSkills DirectorySkills Directory

Ship a skill? Prove it's safe.

Free 120-pattern security scan, letter grade, and an embeddable README badge.

Submit a skill

Related Skills

Rank Tracker

This skill helps you track, analyze, and report on keyword ranking positions over time. It monitors both traditional SERP rankings and AI/GEO visibility to provide comprehensive search performance insights.

1821 votes

Youtube Competitor Analyzer

Find and analyze YouTube competitor channels using YouTube Data API v3. Discover competitors through keyword search, category matching, content similarity, and related channel discovery. Compare metrics, content strategies, and market positioning. Use when users want to (1) Find competitors for their YouTube channel, (2) Analyze competitor performance metrics, (3) Compare their channel against competitors, (4) Identify content gaps and opportunities, (5) Benchmark against similar creators, (6...

31 votes

Xlsx

Use this skill any time a spreadsheet file is the primary input or output. This means any task where the user wants to: open, read, edit, or fix an existing .xlsx, .xlsm, .xltx, .csv, or .tsv file (e.g., adding columns, computing formulas, formatting, charting, cleaning messy data); create a new spreadsheet from scratch or from other data sources; or convert between tabular file formats. Trigger especially when the user references a spreadsheet file by name or path — even casually (like \"the...

1798860 votes

Weather Fetcher

Instructions for fetching current weather temperature data for Karachi, Pakistan from wttr.in API

672240 votes

Weather

Get current weather and forecasts (no API key required).

486960 votes
View all in data →