Help us improve
Share bugs, ideas, or general feedback.
Share bugs, ideas, or general feedback.
Share bugs, ideas, or general feedback.
By willwebster5
Build CrowdStrike Falcon Fusion SOAR workflows — discover actions via live API, author YAML, validate locally, and deploy automation playbooks.
npx claudepluginhub willwebster5/agent-skills --plugin crowdstrike-fusion-workflowsA Claude Code plugin marketplace — a collection of CrowdStrike security skills and plugins.
Add this marketplace to your Claude Code setup:
/plugin marketplace add willwebster5/agent-skills
Then browse and install available plugins:
/plugin search
| Plugin | Description |
|---|---|
crowdstrike-soc | Unified SOC analyst workflow — triage alerts, investigate, hunt threats, tune detections, manage cases |
crowdstrike-soc-agents | Agent-delegated SOC workflow — distributes triage and investigation across specialized sub-agents |
| Plugin | Description |
|---|---|
crowdstrike-logscale-security-queries | Develop and troubleshoot CQL security detection queries for LogScale |
crowdstrike-detection-tuning | Tune NGSIEM detections for false positive reduction with 38 enrichment functions |
crowdstrike-behavioral-detections | Design multi-event behavioral detection rules using correlate() |
crowdstrike-cql-patterns | Curated CQL detection engineering pattern catalog for NG-SIEM |
| Plugin | Description |
|---|---|
crowdstrike-threat-hunting | Autonomous PEAK-framework threat hunting against NG-SIEM — hypothesis, intelligence, and baseline hunts |
crowdstrike-source-threat-modeling | Threat-model-first detection planning for data sources without OOTB coverage |
| Plugin | Description |
|---|---|
crowdstrike-fusion-workflows | Build Falcon Fusion SOAR workflows — discover actions, author YAML, validate |
crowdstrike-response-playbooks | Detection-to-response mapping and SOAR playbook design with tiered response actions |
MIT
Share bugs, ideas, or general feedback.
Based on adoption, maintenance, documentation, and repository signals. Not a security audit or endorsement.
Detection-to-response mapping and SOAR playbook design — analyzes detections, recommends tiered response actions, and produces handoff docs for Falcon Fusion workflow generation.
Create, validate, import, execute, and export CrowdStrike Falcon Fusion SOAR workflows using natural language.
Advanced LimaCharlie skills for MSSP reporting, fleet coverage, threat intelligence, adapter management, IaC, onboarding, and HTML dashboards. Requires lc-essentials plugin.
Agentic SOC Platform integration for Claude Code
Claude plugins for Blumira - SIEM findings management, device inventory, MSP multi-tenant operations, and security posture analysis
Security operations including SIEM rule design, detection engineering, vulnerability management, security monitoring, and threat intelligence integration.
Agent-delegated SOC workflow for CrowdStrike NGSIEM — distributes triage, investigation, and evidence collection across specialized sub-agents (Haiku for mechanical, Sonnet for substantive, Opus for judgment).
Curated CQL detection engineering pattern catalog for CrowdStrike NG-SIEM — correlation, enrichment, aggregation, scoring, baselining, and more.
Autonomous threat hunting using the PEAK framework — hypothesis-driven, intelligence-driven, and baseline hunts against CrowdStrike NG-SIEM with hunt reports and detection backlogs.
Analyze and tune CrowdStrike NGSIEM detections for false positive reduction using 38 enrichment functions across AWS, EntraID, GitHub, and network data sources.
Develop, optimize, and troubleshoot CrowdStrike LogScale security detection queries using CQL — includes case statements, multi-event correlation, investigation playbooks, and hunting rules.
Own this plugin?
Verify ownership to unlock analytics, metadata editing, and a verified badge.
Sign in to claimOwn this plugin?
Verify ownership to unlock analytics, metadata editing, and a verified badge.
Sign in to claim