npx claudepluginhub plurigrid/asi --plugin asiThis skill uses the workspace's default tool permissions.
SIEM use case tuning reduces alert fatigue by systematically analyzing detection rules for false positive rates, adjusting thresholds based on environmental baselines, creating context-aware whitelists, and measuring detection efficacy through precision/recall metrics. This skill covers tuning workflows for Splunk correlation searches and Elastic detection rules, including statistical baselinin...
Tunes SIEM detection rules in Splunk and Elastic to reduce false positives: analyzes alert volumes, creates whitelists, adjusts thresholds, measures precision/recall efficacy.
Tunes SIEM detection rules in Splunk and Elastic by analyzing alert volumes, creating whitelists, adjusting thresholds, and measuring precision/recall to reduce false positives.
Performs SIEM false positive reduction via rule tuning, threshold adjustment, allowlists, correlation refinement, and Splunk SPL queries to combat SOC alert fatigue.
Share bugs, ideas, or general feedback.
SIEM use case tuning reduces alert fatigue by systematically analyzing detection rules for false positive rates, adjusting thresholds based on environmental baselines, creating context-aware whitelists, and measuring detection efficacy through precision/recall metrics. This skill covers tuning workflows for Splunk correlation searches and Elastic detection rules, including statistical baselining, exclusion list management, and alert-to-incident conversion tracking.
requests libraryJSON report with per-rule tuning recommendations including current FP rate, suggested threshold adjustments, whitelist entries, and projected alert reduction percentages.