⚡AgentSkills
🛡️ Cyber Defense & SOC · SOC Operations

Map log source coverage to attack surface

Inventory what you can see versus what attacks require, closing blind spots deliberately.

intermediate~35 minSOC AnalystsDetection EngineersThreat Hunters

Steps

  1. 1List top MITRE techniques relevant to your industry threat profile
  2. 2Map each to required telemetry source and current ingestion status
  3. 3Score coverage: full / partial / none per technique
  4. 4Prioritize gaps by likelihood × detection-value
  5. 5Fund onboarding of highest-value sources with success tests
  6. 6Re-map quarterly; infrastructure drifts silently

Common Pitfalls

  • ▲Ingesting everything equally, cost exploding value flat
  • ▲Coverage assumed rather than tested with synthetic events

Commands

Install with skills CLI
$ npx skills add aniruddhaadak80/skills --skill soc-operations-log-source-coverage
Install globally
$ npx skills add aniruddhaadak80/skills --skill soc-operations-log-source-coverage -g

Tags

#visibility#logging#coverage#cyber-defense-ops#soc-operations

Related skills

Enrichment order, true/false-positive calls with evidence, and escalation criteria applied identically every shift.

🛡️ Cyber Defense & SOC·~25m

Structured hunts starting from TTP intelligence, producing detections or documented negatives.

🛡️ Cyber Defense & SOC·~45m