skills/security-operations/SKILL.md
Use this skill when you need SOC (Security Operations Center) setup or management, threat detection and hunting programs, incident response coordination, SIEM configuration and tuning, security monitoring strategy, SRE security integration, or security operations metrics and KPIs. Trigger for active threats, SOC buildout, or operational security program design.
npx skillsauth add aviskaar/open-org security-operationsInstall this skill globally with one command. Works with Claude Code, Cursor, and Windsurf.
3 of 9 scanners reported clean
Some scanners were skipped, did not run, or reported a non-clean status. Review each row below.
VP Security Operations owns the 24×7 detection, response, and resilience capability. This skill orchestrates the SOC, threat hunting program, incident response lifecycle, and SRE-security integration to ensure continuous monitoring, rapid detection, and effective containment.
SOC maturity model:
| Level | Capability | Description | |---|---|---| | L1 | Alert Triage | Ingest logs, triage alerts, escalate | | L2 | Investigation | Deep analysis, threat intel correlation | | L3 | Threat Hunting | Proactive hunt, adversary emulation | | L4 | Engineering | Detection engineering, toolchain dev | | L5 | Strategic | Program governance, threat intelligence |
SIEM architecture requirements:
Required log sources (non-negotiable):
Identity: Active Directory / Entra ID / Okta / IAM
Endpoints: EDR (CrowdStrike/SentinelOne/Defender)
Network: Firewall, IDS/IPS, DNS, DHCP, proxy
Cloud: CloudTrail/Audit Logs (AWS/Azure/GCP)
Applications: WAF, API gateway, application logs
Email: O365/Google Workspace security events
Data: DLP events, database audit logs
Physical: Badge access, CCTV event integrations
Detection rule tiers:
MITRE ATT&CK coverage targets:
Initial Access: ≥90% detection coverage
Execution: ≥85%
Persistence: ≥80%
Privilege Escalation: ≥90%
Defense Evasion: ≥70%
Credential Access: ≥90%
Discovery: ≥60%
Lateral Movement: ≥85%
Collection: ≥75%
Exfiltration: ≥80%
Command & Control: ≥85%
Impact: ≥90%
Alert quality standards:
Severity classification:
| Severity | Definition | Response SLA | Escalation | |---|---|---|---| | P1 — Critical | Active breach, data exfiltration, ransomware | 15 min acknowledge, 1h contain | CISO + Legal + Exec | | P2 — High | Confirmed compromise, insider threat | 1h acknowledge, 4h contain | security-operations VP + CISO | | P3 — Medium | Suspicious activity, policy violation | 4h acknowledge, 24h investigate | L2 SOC | | P4 — Low | Informational, compliance flag | 24h acknowledge, 72h close | L1 SOC |
IR lifecycle (delegate to incident-responder):
Playbook requirements:
Delegate to threat-hunter for execution.
Hunting cadence:
Hunt hypothesis sources:
Operational KPIs (track weekly):
| Metric | Target | Critical Threshold | |---|---|---| | MTTD (Mean Time to Detect) | <1 hour | >4 hours → escalate | | MTTR (Mean Time to Respond) | <4 hours | >24 hours → escalate | | Alert Volume | Baseline ±20% | >50% spike → investigation | | False Positive Rate | <10% | >25% → rule review | | P1 Incident Count | 0 per month | Any P1 → CISO report | | Hunt Coverage (ATT&CK) | ≥80% techniques | <60% → gap report | | SOC Analyst Utilization | 70–85% | >90% → staff review | | Playbook Currency | 100% reviewed annually | Any expired → immediate |
Delegate to sre-operations for reliability + security fusion.
Integration requirements:
documentation
Replace with a description of the skill and when the agent should use it. Write this as a trigger condition: 'Use this skill when...'
development
Use this skill when a marketing team needs to produce a credibility-building whitepaper by collaborating with engineering, product, sales, and C-level teams. Covers topic selection, stakeholder interviews, research synthesis, writing, design briefing, gated landing page setup, and distribution to investors, enterprise buyers, and industry analysts.
development
Use this skill when you need proactive threat hunting campaigns, MITRE ATT&CK-based hunt hypotheses, IOC sweeps, behavioral anomaly investigation, threat intelligence integration, adversary emulation planning, SOC analyst triage support, SIEM query development (KQL/SPL/YARA), or automated threat detection engineering. Trigger for threat hunting sprints, new threat intel indicators, or post-incident proactive sweeps.
testing
Use this skill when a VP Tax, Tax Manager, Controller, or Finance Director needs to manage all tax obligations of a company — including corporate income tax, GST/VAT/Sales Tax, payroll taxes, transfer pricing, R&D tax credits, and multi-jurisdictional tax compliance. Trigger when computing tax provisions, preparing tax filings, responding to tax authority notices, evaluating tax implications of business decisions (new geographies, M&A, restructuring), managing indirect taxes on invoices, or producing the tax compliance calendar with all deadlines for the CFO and board.