Splunk AI security skills
Alert triage, SPL drafting, detection tuning, incident timelines, and SOC handoffs.
Security tool skills
Practical, evidence-first workflows for using AI with SIEM, CNAPP, endpoint, identity, AppSec, vulnerability management, and model gateway tools without losing control.
Alert triage, SPL drafting, detection tuning, incident timelines, and SOC handoffs.
Attack path summaries, exposure prioritization, cloud ownership, and remediation planning.
Firewall policy review, Prisma Cloud risk summaries, Cortex investigations, and change review.
Endpoint process tree summaries, containment notes, threat hunting, and incident updates.
KQL query drafting, incident summaries, Microsoft 365 investigations, and automation review.
Suspicious login review, policy analysis, access review, identity incident recovery, and blast-radius summaries.
Pull request security review, code scanning triage, secret response, dependency review, and CI/CD checks.
Vulnerability clustering, container triage, SBOM review, IaC remediation, and risk briefs.
Model gateway policy review, virtual key control, token budgets, prompt log triage, and provider routing.
Operating model
Splunk events, Wiz graph paths, CrowdStrike detections, Okta logs, GitHub alerts, and Trivy findings should remain traceable in every AI-generated summary.
Let AI draft queries, tickets, summaries, and remediation plans. Keep containment, policy changes, identity changes, and production deploys behind human review.