Help us improve
Share bugs, ideas, or general feedback.
Share bugs, ideas, or general feedback.
Share bugs, ideas, or general feedback.
By willwebster5
Agent-delegated SOC workflow for CrowdStrike NGSIEM — distributes triage, investigation, and evidence collection across specialized sub-agents (Haiku for mechanical, Sonnet for substantive, Opus for judgment).
npx claudepluginhub willwebster5/agent-skills --plugin crowdstrike-soc-agentsA Claude Code plugin marketplace — a collection of CrowdStrike security skills and plugins.
Add this marketplace to your Claude Code setup:
/plugin marketplace add willwebster5/agent-skills
Then browse and install available plugins:
/plugin search
| Plugin | Description |
|---|---|
crowdstrike-soc | Unified SOC analyst workflow — triage alerts, investigate, hunt threats, tune detections, manage cases |
crowdstrike-soc-agents | Agent-delegated SOC workflow — distributes triage and investigation across specialized sub-agents |
| Plugin | Description |
|---|---|
crowdstrike-logscale-security-queries | Develop and troubleshoot CQL security detection queries for LogScale |
crowdstrike-detection-tuning | Tune NGSIEM detections for false positive reduction with 38 enrichment functions |
crowdstrike-behavioral-detections | Design multi-event behavioral detection rules using correlate() |
crowdstrike-cql-patterns | Curated CQL detection engineering pattern catalog for NG-SIEM |
| Plugin | Description |
|---|---|
crowdstrike-threat-hunting | Autonomous PEAK-framework threat hunting against NG-SIEM — hypothesis, intelligence, and baseline hunts |
crowdstrike-source-threat-modeling | Threat-model-first detection planning for data sources without OOTB coverage |
| Plugin | Description |
|---|---|
crowdstrike-fusion-workflows | Build Falcon Fusion SOAR workflows — discover actions, author YAML, validate |
crowdstrike-response-playbooks | Detection-to-response mapping and SOAR playbook design with tiered response actions |
MIT
Share bugs, ideas, or general feedback.
Based on adoption, maintenance, documentation, and repository signals. Not a security audit or endorsement.
Unified SOC analyst workflow for CrowdStrike NGSIEM — triage alerts, investigate security events, hunt threats, tune detections, and manage cases through a phased lifecycle.
Agentic SOC Platform integration for Claude Code
Core LimaCharlie skills for CLI-based API access, detection engineering, sensor tasking, case investigation, and fleet health monitoring.
Create, validate, import, execute, and export CrowdStrike Falcon Fusion SOAR workflows using natural language.
Security operations including SIEM rule design, detection engineering, vulnerability management, security monitoring, and threat intelligence integration.
Claude plugins for RocketCyber managed SOC - incidents, agents, accounts, threat detection
Curated CQL detection engineering pattern catalog for CrowdStrike NG-SIEM — correlation, enrichment, aggregation, scoring, baselining, and more.
Build CrowdStrike Falcon Fusion SOAR workflows — discover actions via live API, author YAML, validate locally, and deploy automation playbooks.
Autonomous threat hunting using the PEAK framework — hypothesis-driven, intelligence-driven, and baseline hunts against CrowdStrike NG-SIEM with hunt reports and detection backlogs.
Analyze and tune CrowdStrike NGSIEM detections for false positive reduction using 38 enrichment functions across AWS, EntraID, GitHub, and network data sources.
Develop, optimize, and troubleshoot CrowdStrike LogScale security detection queries using CQL — includes case statements, multi-event correlation, investigation playbooks, and hunting rules.
Own this plugin?
Verify ownership to unlock analytics, metadata editing, and a verified badge.
Sign in to claimOwn this plugin?
Verify ownership to unlock analytics, metadata editing, and a verified badge.
Sign in to claim