security-analyst

Analyze Wazuh SIEM/XDR alert reports to uncover threats and propose remediation steps.

1|Updated Apr 3, 2026
One-click install
npx skills add https://github.com/danielpsf/homelab --skill security-analyst-danielpsf
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: security-analyst
Source: https://github.com/danielpsf/homelab/tree/main/.opencode/skills/security-analyst
Command: npx skills add https://github.com/danielpsf/homelab --skill security-analyst-danielpsf

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

Analyze Wazuh SIEM/XDR security alert reports to uncover threats, correlate events, and propose actionable remediation guidance.

Core Features & Use Cases

  • Correlate Wazuh digest alerts to identify attack chains and risk hotspots.
  • Propose concrete remediation steps with commands and configuration changes.
  • Enable proactive security assessments and rule-tuning based on historical context.

Quick Start

Use this skill to analyze a Wazuh alert digest and produce a structured remediation plan.

Frequently Asked Questions about security-analyst

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I analyze Wazuh alerts to identify attack patterns and propose remediation?

To analyze Wazuh alerts, supply a Markdown digest of your SIEM or XDR reports. The system cross-references previous alerts, identifies patterns, assesses risk with MITRE mapping, and outputs structured findings with recommended remediation steps and supporting commands.

Can I map Wazuh SIEM security alerts to MITRE ATT&CK techniques automatically?

Yes, Wazuh security alerts can be mapped to MITRE techniques automatically. The analysis correlates digest events to uncover threats and assesses risk using MITRE mapping, providing actionable remediation guidance and configuration changes.

What is the best way to correlate Wazuh digest alerts to find risk hotspots?

The best way to correlate Wazuh digest alerts is to apply historical context to the supplied reports. This process cross-references previous alerts to identify attack chains, uncovers threats, and highlights risk hotspots within your security environment.

Does analyzing Wazuh XDR alerts with this method preserve sensitive data locally?

Yes, analyzing Wazuh XDR alerts preserves sensitive data locally. The analysis processes supplied Markdown digests and live system context on your local machine while outputting structured findings and supporting commands without exposing sensitive information externally.

How do I generate automated fixes and configuration changes for Wazuh security threats?

You generate automated fixes by providing a Wazuh alert digest for analysis. The system evaluates the security alerts, identifies patterns, and proposes concrete remediation steps with specific commands and configuration changes to resolve the detected threats.

When do I need a Markdown digest to investigate Wazuh security alerts?

You need a Markdown digest when you want to perform a proactive security assessment or investigate Wazuh alerts. Supplying this format allows the analysis to correlate events, apply MITRE mapping, and output a structured remediation plan based on historical context.