Skill Claude Code
Route SOC work across the agent swarm — decide which specialist handles a case next, write a complete handoff message, and stop cleanly; use whenever you are the commander or must decide who acts next.
Agentic SOC for Wazuh built on Strands Agents: a 13-agent swarm with 37 Wazuh-verified skills triages, investigates and plans response through the Wazuh MCP Server. Policy-gated autonomy, approvals, RBAC, audit, tracing and evals in one Docker stack. Bedrock, Anthropic, NVIDIA NIM, vLLM, LiteLLM or air-gapped Ollama.
Skill Claude Code
Route SOC work across the agent swarm — decide which specialist handles a case next, write a complete handoff message, and stop cleanly; use whenever you are the commander or must decide who acts next.
Skill Claude Code
Assess possible threat-actor or campaign links using the Diamond Model and ATT&CK group data, expressed with calibrated estimative language; use only when a case shows enough TTP or infrastructure overlap to justify attribution discussion.
Skill Claude Code
Run hypothesis-driven threat hunts over Wazuh data using the PEAK framework (hypothesis, baseline, model-assisted), record outcomes, and hand confirmed patterns to detection engineering; use for scheduled hunts or when asked to look for undetected activity.
Skill Claude Code
Prioritize Wazuh vulnerability-detector findings with CISA KEV, FIRST EPSS, CVSS and asset context into CISA SSVC decisions and remediation SLAs; use for vulnerability sweeps, CVE alerts or patch-priority questions.
Skill Claude Code
How Wazuh active response actually works — commands, agent-side scripts, dispatch vs execution, permanence, blast radius, pre-checks and verification caveats — for planning and verifying containment; use before proposing or verifying any response action.
Skill Claude Code
Interpret Wazuh cloud and container alerts — AWS (CloudTrail, GuardDuty, VPC Flow, Security Hub), Azure, GCP, Microsoft Graph, Office 365, GitHub and Docker — with their key fields, normal baselines and pivots; use for any alert from a cloud or container integration.
Skill Claude Code
Investigate Wazuh File Integrity Monitoring (syscheck) alerts — file and registry add/modify/delete events, checksums, permissions and who-data — separate tampering from routine change and pivot to processes and users; use for any syscheck alert or suspected persistence/tampering.
Skill Claude Code
Interpret Wazuh malware signals — rootcheck, VirusTotal and ClamAV integrations, Microsoft Antimalware events, Sysmon detections and suspicious binaries — and turn them into enrichment and containment hand-offs; use for any malware, rootkit or suspicious-binary alert.
Skill Claude Code
How to query Wazuh through the Wazuh MCP Server efficiently and correctly — which tool answers which question, parameter syntax and pitfalls, result format, truncation, token budget and error handling; load before your first Wazuh query in a run.
Skill Claude Code
Keep the Wazuh platform trustworthy — agent connectivity and version drift, manager and cluster health, event queue flooding and dropped events, silent log sources, FIM capacity and rule/decoder errors — and raise detection blind spots as cases; use for the scheduled platform health check or whenever data looks…
Skill Claude Code
Read Wazuh alerts correctly — alert anatomy, the 0–15 level scale, composite and correlation rules, compliance and MITRE tags, decoders, custom rules and noise tuning; use when interpreting what a rule really means or when proposing rule changes.
Skill Claude Code
Use Wazuh Security Configuration Assessment (SCA) results — CIS policy scores, failed checks and regressions — to prioritize hardening and map it to CIS Controls, PCI DSS and ISO 27001; use for hardening reviews, compliance evidence, or when a vulnerability or incident points to a misconfiguration.
Skill Claude Code
Interpret Wazuh Windows EventChannel and Sysmon alerts — logon, privilege, account and service events, Sysmon detection groups, field paths and logon types — mapping Windows Event IDs to Wazuh rules; use for any Windows or Sysmon alert and for Windows-focused hunts.
At most 3 mods per repository are shown here, and a mod shipped inside a plugin is left to that plugin's page — the rest are on their repository pages: