security-operations

Orchestrate SOC incident response and threat hunting across on-premises and cloud environments.

17|1|Updated Jun 8, 2025
One-click install
npx skills add https://github.com/williamzujkowski/standards --skill security-operations
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: security-operations
Source: https://github.com/williamzujkowski/standards/tree/main/skills/security/security-operations
Command: npx skills add https://github.com/williamzujkowski/standards --skill security-operations

SYSTEM DOCUMENTATION & REQUIREMENTS

💡 This Skill includes templates (resource) and resources (resource) components.

What problem does it solve?

Security Operations (SOC) standards cover incident response, SIEM management, and threat hunting aligned with NIST IR controls.

Core Features & Use Cases

  • IR Lifecycle: Preparation, detection/analysis, containment/eradication, and post-incident activity.
  • SIEM & Logging: Centralized logging, correlation rules, and alerting.
  • Threat Hunting: Proactive detection and improvements to defenses.

Quick Start

Establish a SOC playbook with an IR plan, SIEM rules, and a simple threat-hunting routine.

Frequently Asked Questions about security-operations

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I set up incident response workflows for my SOC?

Incident response workflows orchestrate detection, containment, and recovery across your environment. This Skill provides playbook-driven templates and NIST 800-61 aligned procedures for phishing, malware, data breach, DDoS, and insider-threat scenarios, enabling your SOC to respond consistently and measurably.

What's the difference between SIEM tuning and threat hunting?

SIEM tuning configures centralized logging, correlation rules, and alerting to detect known threats automatically. Threat hunting proactively searches for undetected compromise and improves defenses based on findings. This Skill covers both: SIEM setup for reactive detection and hunting routines for continuous improvement.

Can I use this for on-premises and cloud security operations?

Yes. This Skill applies across on-premises and cloud estates, addressing data collection, log management, and SIEM tuning in both environments. Configurations and scripts are reproducible, letting you standardize incident response and threat-hunting practices regardless of infrastructure.

How do I collect and preserve evidence during incident response?

Evidence collection is part of the SOC preparation and detection phases. This Skill defines workflows, evidence-collection procedures, and post-incident reporting that satisfy NIST controls, ensuring forensically sound data capture, chain-of-custody tracking, and reproducible analysis across incident types.

What metrics should I track for SOC incident response?

Key metrics include detection time, containment time, and recovery success rate. This Skill provides templates for defining and measuring these outcomes alongside SIEM performance and threat-hunting effectiveness, helping you quantify SOC maturity and identify improvement gaps.