Help us improve
Share bugs, ideas, or general feedback.
Share bugs, ideas, or general feedback.
Share bugs, ideas, or general feedback.
By willwebster5
Curated CQL detection engineering pattern catalog for CrowdStrike NG-SIEM — correlation, enrichment, aggregation, scoring, baselining, and more.
npx claudepluginhub willwebster5/agent-skills --plugin crowdstrike-cql-patternsA Claude Code plugin marketplace — a collection of CrowdStrike security skills and plugins.
Add this marketplace to your Claude Code setup:
/plugin marketplace add willwebster5/agent-skills
Then browse and install available plugins:
/plugin search
| Plugin | Description |
|---|---|
crowdstrike-soc | Unified SOC analyst workflow — triage alerts, investigate, hunt threats, tune detections, manage cases |
crowdstrike-soc-agents | Agent-delegated SOC workflow — distributes triage and investigation across specialized sub-agents |
| Plugin | Description |
|---|---|
crowdstrike-logscale-security-queries | Develop and troubleshoot CQL security detection queries for LogScale |
crowdstrike-detection-tuning | Tune NGSIEM detections for false positive reduction with 38 enrichment functions |
crowdstrike-behavioral-detections | Design multi-event behavioral detection rules using correlate() |
crowdstrike-cql-patterns | Curated CQL detection engineering pattern catalog for NG-SIEM |
| Plugin | Description |
|---|---|
crowdstrike-threat-hunting | Autonomous PEAK-framework threat hunting against NG-SIEM — hypothesis, intelligence, and baseline hunts |
crowdstrike-source-threat-modeling | Threat-model-first detection planning for data sources without OOTB coverage |
| Plugin | Description |
|---|---|
crowdstrike-fusion-workflows | Build Falcon Fusion SOAR workflows — discover actions, author YAML, validate |
crowdstrike-response-playbooks | Detection-to-response mapping and SOAR playbook design with tiered response actions |
MIT
Share bugs, ideas, or general feedback.
Based on adoption, maintenance, documentation, and repository signals. Not a security audit or endorsement.
Develop, optimize, and troubleshoot CrowdStrike LogScale security detection queries using CQL — includes case statements, multi-event correlation, investigation playbooks, and hunting rules.
Core LimaCharlie skills for CLI-based API access, detection engineering, sensor tasking, case investigation, and fleet health monitoring.
Agentic SOC Platform integration for Claude Code
Security operations including SIEM rule design, detection engineering, vulnerability management, security monitoring, and threat intelligence integration.
Claude plugins for SentinelOne XDR - threat detection, incident response, and endpoint agent management via the Purple AI MCP server
Create, validate, import, execute, and export CrowdStrike Falcon Fusion SOAR workflows using natural language.
Agent-delegated SOC workflow for CrowdStrike NGSIEM — distributes triage, investigation, and evidence collection across specialized sub-agents (Haiku for mechanical, Sonnet for substantive, Opus for judgment).
Build CrowdStrike Falcon Fusion SOAR workflows — discover actions via live API, author YAML, validate locally, and deploy automation playbooks.
Autonomous threat hunting using the PEAK framework — hypothesis-driven, intelligence-driven, and baseline hunts against CrowdStrike NG-SIEM with hunt reports and detection backlogs.
Analyze and tune CrowdStrike NGSIEM detections for false positive reduction using 38 enrichment functions across AWS, EntraID, GitHub, and network data sources.
Develop, optimize, and troubleshoot CrowdStrike LogScale security detection queries using CQL — includes case statements, multi-event correlation, investigation playbooks, and hunting rules.
Own this plugin?
Verify ownership to unlock analytics, metadata editing, and a verified badge.
Sign in to claimOwn this plugin?
Verify ownership to unlock analytics, metadata editing, and a verified badge.
Sign in to claim