siem-log-management
This Claude Code plugin provides expertise in designing SIEM architectures, writing detection queries across Splunk SPL, Elastic KQL/EQL, and Microsoft Sentinel KQL, and correlating events across log sources to find multi-stage attacks. It includes agents for architecture design and log analysis, commands for SIEM setup and threat detection queries, and skills in log correlation patterns and SIEM query language syntax.
Install
Source: https://github.com/HermeticOrmus/LibreSecOps-Claude-Code/tree/HEAD/plugins/siem-log-management
What it's made of
2 commands · 2 agents · 2 skills
- Commands
- 2
- Agents
- 2
- Skills
- 2
- MCP servers
- 0
- Hooks
- 0
What it needs & plugs into
- API keys
- none
- Paid services
- none detected
- External tools
- none
- Talks to
- nothing external detected
Analyzed . Facts extracted from the plugin's files. Prose generated by claude-haiku-4-5-20251001.
Is this your plugin?
Claim it to keep the card accurate and enter the weekly contest. Requires signing in as the GitHub owner (HermeticOrmus).