Skip to main content
← Back to agents

SIEM Query Builder

unreviewed

Generates optimized SIEM queries from natural language threat descriptions.

Author: detection-engineering
Category: skill
Framework: Claude Code SKILL
License: MIT
Added: Apr 3, 2026
View on GitHub →

Integrations

SplunkMicrosoft Sentinel

Tags

detectionSIEMthreat-hunting

Describe a threat scenario in plain English and this SKILL generates optimized SPL (Splunk) or KQL (Sentinel) queries. Supports correlation rules, scheduled searches, and alert thresholds.