Logs

Logs taxonomy generated by the site skill importer.

16 skills
M
analyzing-security-logs-with-splunk

by mukul975

analyzing-security-logs-with-splunk helps investigate security events in Splunk by correlating Windows, firewall, proxy, and authentication logs into timelines and evidence. This analyzing-security-logs-with-splunk skill is a practical guide for Security Audit, incident response, and threat hunting.

Security Audit
Favorites 0GitHub 6.1k
M
analyzing-cloud-storage-access-patterns

by mukul975

analyzing-cloud-storage-access-patterns helps security teams detect suspicious cloud storage access in AWS S3, GCS, and Azure Blob Storage. It analyzes audit logs for bulk downloads, new source IPs, unusual API calls, bucket enumeration, after-hours access, and possible exfiltration using baseline and anomaly checks.

Security Audit
Favorites 0GitHub 6.1k
M
analyzing-azure-activity-logs-for-threats

by mukul975

analyzing-azure-activity-logs-for-threats skill for querying Azure Monitor activity logs and sign-in logs to spot suspicious admin actions, impossible travel, privilege escalation, and resource tampering. Built for incident triage with KQL patterns, an execution path, and practical Azure log table guidance.

Incident Triage
Favorites 0GitHub 6.1k
M
analyzing-api-gateway-access-logs

by mukul975

analyzing-api-gateway-access-logs helps parse API Gateway access logs to detect BOLA/IDOR, rate-limit bypass, credential scanning, and injection attempts. Built for SOC triage, threat hunting, and Security Audit workflows across AWS API Gateway, Kong, and Nginx-style logs using pandas-based analysis.

Security Audit
Favorites 0GitHub 6.1k
M
azure-monitor-query-py

by microsoft

azure-monitor-query-py helps Python developers query Azure Monitor logs and metrics with azure-monitor-query. Use it for Log Analytics workspaces, Azure resource metrics, backend monitoring, diagnostics, and observability automation. It fits the azure-monitor-query-py skill when you already have workspace IDs, resource URIs, and Azure credentials.

Backend Development
Favorites 0GitHub 2.3k
M
detecting-sql-injection-via-waf-logs

by mukul975

Analyze WAF and audit logs to detect SQL injection campaigns with detecting-sql-injection-via-waf-logs. Built for Security Audit and SOC workflows, it parses ModSecurity, AWS WAF, and Cloudflare events, classifies UNION SELECT, OR 1=1, SLEEP(), and BENCHMARK() patterns, correlates sources, and produces incident-oriented findings.

Security Audit
Favorites 0GitHub 0
M
detecting-evasion-techniques-in-endpoint-logs

by mukul975

The detecting-evasion-techniques-in-endpoint-logs skill helps hunt defense evasion in Windows endpoint logs, including log clearing, timestomping, process injection, and security tool disabling. Use it for threat hunting, detection engineering, and incident triage with Sysmon, Windows Security, or EDR telemetry.

Threat Hunting
Favorites 0GitHub 0
M
analyzing-web-server-logs-for-intrusion

by mukul975

The analyzing-web-server-logs-for-intrusion skill parses Apache and Nginx access logs to detect SQL injection, local file inclusion, directory traversal, scanner fingerprints, brute-force bursts, and anomalous request patterns. Use it for intrusion triage, threat hunting, and Security Audit workflows with GeoIP enrichment and signature-based detection.

Security Audit
Favorites 0GitHub 0
M
analyzing-tls-certificate-transparency-logs

by mukul975

The analyzing-tls-certificate-transparency-logs skill helps security teams query Certificate Transparency data with crt.sh, pycrtsh, and related feeds to find suspicious TLS certificates, lookalike domains, typosquatting, and unauthorized issuance. It supports threat hunting, brand protection, and certificate monitoring with a practical workflow and similarity checks.

Threat Intelligence
Favorites 0GitHub 0
M
analyzing-powershell-script-block-logging

by mukul975

analyzing-powershell-script-block-logging skill for parsing Windows PowerShell Script Block Logging Event ID 4104 from EVTX files, reconstructing split script blocks, and flagging obfuscated commands, encoded payloads, Invoke-Expression abuse, download cradles, and AMSI bypass attempts for Security Audit work.

Security Audit
Favorites 0GitHub 0
M
analyzing-linux-audit-logs-for-intrusion

by mukul975

analyzing-linux-audit-logs-for-intrusion is a Linux incident-response skill for auditd review, helping you find suspicious logins, privilege escalation, file tampering, and host intrusion evidence with ausearch, aureport, and auditctl.

Incident Triage
Favorites 0GitHub 0
M
analyzing-kubernetes-audit-logs

by mukul975

analyzing-kubernetes-audit-logs is a Kubernetes security analysis skill for turning API server audit logs into actionable findings. Use it to investigate exec into pods, secret access, RBAC changes, privileged workloads, and anonymous API access, or to build detection rules and triage summaries from JSON lines audit data.

Security Audit
Favorites 0GitHub 0
M
analyzing-docker-container-forensics

by mukul975

analyzing-docker-container-forensics helps investigate compromised Docker containers by analyzing images, layers, volumes, logs, and runtime artifacts to identify malicious activity and preserve evidence. Use this analyzing-docker-container-forensics skill for a Security Audit, incident review, or container hardening assessment.

Security Audit
Favorites 0GitHub 0
M
analyzing-dns-logs-for-exfiltration

by mukul975

analyzing-dns-logs-for-exfiltration helps SOC analysts detect DNS tunneling, DGA-like domains, TXT abuse, and covert C2 patterns from SIEM or Zeek logs. Use it for Security Audit workflows when you need entropy analysis, query-volume anomalies, and practical triage guidance.

Security Audit
Favorites 0GitHub 0
O
sentry

by openai

The sentry skill is a read-only Observability tool for inspecting Sentry issues, events, and health signals. Use it to investigate recent production errors, summarize impact, and run repeatable CLI-based queries with structured output. It is best when you need a practical sentry guide for triage, not a broad observability overview.

Observability
Favorites 0GitHub 0
M
azure-monitor-opentelemetry-exporter-py

by microsoft

azure-monitor-opentelemetry-exporter-py helps you set up low-level OpenTelemetry export from Python to Azure Monitor and Application Insights. Use it when you need a custom observability pipeline with direct control over traces, metrics, and logs, not a higher-level auto-instrumentation distro.

Observability
Favorites 0GitHub 0