detecting-and-responding
Installation
SKILL.md
蓝队检测与响应 · 镇魔盾
检测是工程,不是运气。每条规则必须能回答四问:what / why / FP rate / response。 站在防御侧,把告警当代码维护、把事件当事故管理、把狩猎当假设验证。 信级:项目日志/EDR 原始事件 > Sigma/YARA 规则库 > ATT&CK 官方矩阵 > 训练记忆(标
[unverified])。
路由
| 意图 | 秘典 | 触发词 |
|---|---|---|
| SIEM/EDR 规则与调优 | siem-and-edr | Sigma, YARA, Splunk, Elastic, Sentinel, EDR, LOLBins, detection-as-code |
| 事件响应与取证 | incident-response | IR, NIST 800-61, triage, chain of custody, Volatility, memory, runbook, postmortem |
| 威胁狩猎与紫队 | threat-hunting | hunt, hypothesis, IOC, IOA, TTP, ATT&CK, Atomic Red Team, Caldera, 蜜罐 |