What problem does it solve?
SOC leaders lack quantified visibility into operational performance, making it hard to justify staffing, prove tool ROI, satisfy compliance audits, or report security posture to executives. This Skill turns raw SIEM incident data into measurable KPIs like MTTD, MTTR, false positive rates, and detection coverage.
Core Features & Use Cases
- MTTD/MTTR Measurement: Splunk SPL queries compute mean, median, and percentile detection and response times by urgency, with trend tracking over 90 days.
- Alert Quality & Analyst Productivity: Disposition analysis (TP/FP rates, signal-to-noise ratio), per-analyst triage times, and shift-based workload distribution.
- Detection Coverage Tracking: ATT&CK technique coverage scoring via lookup joins and data source ingestion validation.
- Executive Reporting: Monthly scorecards, month-over-month comparisons, and continuous improvement initiative tracking.
- Use Case: A SOC manager preparing a quarterly business review uses the provided queries to show MTTD dropped 12%, alert volume fell 84% after risk-based alerting, and ATT&CK coverage reached 64%.
Quick Start
Build a SOC performance dashboard from my Splunk notable index showing MTTD, MTTR, false positive rate, and ATT&CK coverage for the last 30 days.