Agent skill

Performing False Positive Reduction In Siem

by mukul975 in mukul975/Anthropic-Cybersecurity-Skills

Reduces SIEM false positives through systematic rule tuning, threshold adjustment, correlation logic refinement, allowlisting, and threat intelligence enrichment.

Apache-2.0Auto-check passedSecurity

Install Performing False Positive Reduction In Siem

skills CLI
$ npx skills add mukul975/Anthropic-Cybersecurity-Skills --skill performing-false-positive-reduction-in-siem -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install mukul975/Anthropic-Cybersecurity-Skills performing-false-positive-reduction-in-siem --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/mukul975/Anthropic-Cybersecurity-Skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/performing-false-positive-reduction-in-siem .claude/skills/performing-false-positive-reduction-in-siem && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
performing-false-positive-reduction-in-siem
GitHub stars
34k
Token cost
~1.9k tokens
SKILL.md length
365 words
Files
8 (incl. scripts, references, assets)
Skills in repo
644
Repo updated
First seen
Licence
Apache-2.0

At a glance

Reduces SIEM false positives through systematic rule tuning, threshold adjustment, correlation logic refinement, allowlisting, and threat intelligence enrichment.

  • Works in 12 steps: Identify the Noisiest Rules → Threshold Tuning → Allowlist/Exclusion Management → …
  • SOC analysts are overwhelmed by alert noise
  • SKILL.md covers Overview, When to Use, Prerequisites and False Positive Reduction…, plus 4 more sections
  • Runs Python scripts from its folder

What it does

Performing False Positive Reduction In Siem is an agent skill from mukul975/Anthropic-Cybersecurity-Skills. Reduces SIEM false positives through systematic rule tuning, threshold adjustment, correlation logic refinement, allowlisting, and threat intelligence enrichment. Use when SOC analysts are overwhelmed by alert noise, when tuning noisy detection rules, or during a quarterly SIEM rule review to cut alert fatigue.

Its SKILL.md is about 1.9k tokens, which your agent loads only when the skill is triggered. The skill folder holds 10 other files, including scripts, reference files and assets (for example `assets/template.md`, `references/api-reference.md` and `references/standards.md`).

It sits in Security, covering Security operations and OSINT. The repository describes itself as: 817 structured cybersecurity skills for AI agents · Mapped to 6 frameworks: MITRE ATT&CK, NIST CSF 2.0, MITRE ATLAS, D3FEND, NIST AI RMF & MITRE F3 (Fight Fraud) · agentskills.io…. The licence is Apache-2.0.

When your agent uses it

  • SOC analysts are overwhelmed by alert noise
  • Tuning noisy detection rules
  • During a quarterly SIEM rule review to cut alert fatigue

Example prompts

  • “Use the performing-false-positive-reduction-in-siem skill to reduce SIEM false positives through systematic rule tuning, threshold adjustment…”
  • “/performing-false-positive-reduction-in-siem”

Requirements

  • Python 3

Workflow steps

12 steps, taken from the step headings in SKILL.md.

  1. Identify the Noisiest Rules
  2. Threshold Tuning
  3. Allowlist/Exclusion Management
  4. Correlation Enhancement
  5. Time-Based Exclusions
  6. Behavioral Baseline Integration
  7. Threat Intelligence Filtering
  8. Identify (Weekly)
  9. Analyze (Weekly)
  10. Tune (Bi-weekly)
  11. Validate (Monthly)
  12. Report (Quarterly)

What it can do on your machine

Read from SKILL.md and the folder at commit 54a7988. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Ships 2 files in scripts/ (Python), which the agent can run.

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Links to these hosts (documentation or services it may open):

    • cybersierra.co
    • connectwise.com
    • prophetsecurity.ai
    • manageengine.com

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Performing False Positive Reduction In Siem loads about 1.9k tokens when it runs, and up to ~2.7k if it reads all its reference files. Until then it costs about 89 tokens; SKILL.md has 365 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~89
When it runs · the whole SKILL.md, loaded when a task matches
~1.9k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~2.7k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.

SKILL.md

The full file from mukul975/Anthropic-Cybersecurity-Skills at commit 54a7988, republished under its Apache-2.0 licence (© mukul975). 365 words, ~1,882 tokens.

Download SKILL.mdSave it as .claude/skills/performing-false-positive-reduction-in-siem/SKILL.md (or your agent's skills folder). This skill also uses 7 other files; get the full folder from GitHub.
name
performing-false-positive-reduction-in-siem
description
Reduces SIEM false positives through systematic rule tuning, threshold adjustment, correlation logic refinement, allowlisting, and threat intelligence enrichment. Use when SOC analysts are overwhelmed by alert noise, when tuning noisy detection rules, or during a quarterly SIEM rule review to cut alert fatigue.
domain
cybersecurity
subdomain
soc-operations
tags
siem, false-positive, alert-tuning, detection-engineering, alert-fatigue, soc, correlation
version
1.0
author
mahipal
license
Apache-2.0
d3fend_techniques
Token Binding, Restore Access, Password Authentication, Reissue Credential, Strong Password Policy
nist_csf
DE.CM-01, DE.AE-02, RS.MA-01, DE.AE-06
mitre_attack
T1078, T1685.002, T1685.005, T1566

Performing False Positive Reduction in SIEM

Overview

False positive alerts are non-malicious events that trigger security rules, overwhelming SOC analysts with noise. Studies show that up to 45% of SIEM alerts are false positives, and a typical SOC analyst can only investigate 20-25 alerts per shift effectively. Reducing false positives requires systematic tuning across thresholds, correlation logic, allowlists, enrichment, and continuous validation. SIEM rules should be reviewed on a quarterly cycle at minimum.

When to Use

  • When conducting security assessments that involve performing false positive reduction in siem
  • When following incident response procedures for related security events
  • When performing scheduled security testing or auditing activities
  • When validating security controls through hands-on testing

Prerequisites

  • Familiarity with soc operations concepts and tools
  • Access to a test or lab environment for safe execution
  • Python 3.8+ with required dependencies installed
  • Appropriate authorization for any testing activities

False Positive Reduction Techniques

1. Identify the Noisiest Rules
spl
# Splunk - Top 10 noisiest correlation searches
index=notable
| stats count by rule_name
| sort -count
| head 10
| eval pct=round(count / total * 100, 1)
spl
# False positive rate per rule
index=notable
| stats count as total
    count(eval(status_label="Closed - False Positive")) as false_positives
    count(eval(status_label="Closed - True Positive")) as true_positives
    by rule_name
| eval fp_rate=round(false_positives / total * 100, 1)
| sort -fp_rate
| where total > 10
2. Threshold Tuning
spl
# Before: Too sensitive - fires on 5 failed logins
index=wineventlog EventCode=4625
| stats count by src_ip
| where count > 5

# After: Tuned - requires 20+ failures across 3+ accounts in 10 minutes
index=wineventlog EventCode=4625
| bin _time span=10m
| stats count dc(TargetUserName) as unique_accounts by src_ip, _time
| where count > 20 AND unique_accounts > 3
3. Allowlist/Exclusion Management
spl
# Create allowlist lookup for known benign sources
| inputlookup fp_allowlist.csv
| fields src_ip, reason, approved_by, expiry_date

# Apply allowlist in detection rule
index=wineventlog EventCode=4625
| lookup fp_allowlist src_ip OUTPUT reason as allowlisted_reason
| where isnull(allowlisted_reason)
| stats count dc(TargetUserName) as unique_accounts by src_ip
| where count > 20 AND unique_accounts > 3
4. Correlation Enhancement
spl
# Before: Single-event detection (noisy)
index=wineventlog EventCode=4688 New_Process_Name="*powershell.exe"
| eval severity="medium"

# After: Multi-signal correlation (precise)
index=wineventlog EventCode=4688 New_Process_Name="*powershell.exe"
| join src_ip type=left [
    search index=wineventlog EventCode=4625
    | stats count as failed_logins by src_ip
]
| join Computer type=left [
    search index=sysmon EventCode=3
    | stats dc(DestinationIp) as unique_external_connections by Computer
    | where unique_external_connections > 10
]
| where isnotnull(failed_logins) OR unique_external_connections > 10
| eval severity=case(
    failed_logins > 10 AND unique_external_connections > 10, "critical",
    failed_logins > 5 OR unique_external_connections > 5, "high",
    true(), "medium"
)
5. Time-Based Exclusions
spl
# Exclude known maintenance windows
| eval hour=strftime(_time, "%H")
| eval day=strftime(_time, "%A")
| where NOT (hour >= "02" AND hour <= "04" AND day="Sunday")

# Exclude known batch job schedules
| lookup scheduled_tasks_allowlist process_name, schedule_time
    OUTPUT is_scheduled
| where isnull(is_scheduled)
6. Behavioral Baseline Integration
spl
# Build baseline for user login patterns
index=wineventlog EventCode=4624
| bin _time span=1h
| stats count as logins dc(Computer) as unique_hosts by TargetUserName, _time
| eventstats avg(logins) as avg_logins stdev(logins) as stdev_logins
    avg(unique_hosts) as avg_hosts stdev(unique_hosts) as stdev_hosts
    by TargetUserName
| where logins > (avg_logins + 3 * stdev_logins)
    OR unique_hosts > (avg_hosts + 3 * stdev_hosts)
7. Threat Intelligence Filtering
spl
# Only alert when destination matches known threat intelligence
index=firewall action=allowed direction=outbound
| lookup ip_threat_intel_lookup ip as dest_ip OUTPUT threat_type, confidence
| where isnotnull(threat_type) AND confidence > 70
# This eliminates FPs from flagging connections to benign IPs

Tuning Process Framework

Step 1: Identify (Weekly)
  • Pull top 10 rules by alert volume
  • Calculate FP rate for each
  • Identify rules with FP rate > 30%
Step 2: Analyze (Weekly)
  • Sample 20 false positives per rule
  • Categorize root cause of each FP
  • Identify common patterns
Show full SKILL.md (150 more words)Show less
Step 3: Tune (Bi-weekly)
  • Adjust thresholds based on baseline data
  • Add allowlist entries for benign patterns
  • Enhance correlation logic
  • Add enrichment context
Step 4: Validate (Monthly)
  • Run Atomic Red Team tests to verify true positives still trigger
  • Calculate new FP rate after tuning
  • Document tuning rationale
  • Review with detection engineering team
Step 5: Report (Quarterly)
  • FP reduction metrics per rule
  • Overall alert volume trends
  • Analyst productivity improvements
  • Rules retired or replaced

Validation Testing

bash
# Run Atomic Red Team test after tuning to confirm detection still works
# Example: Test brute force detection after threshold adjustment
Invoke-AtomicTest T1110.001 -TestNumbers 1
spl
# Verify detection still triggers after tuning
index=notable rule_name="Brute Force Detection"
earliest=-24h
| stats count
| where count > 0

FP Reduction Metrics

MetricFormulaTarget
False Positive RateFP / (FP + TP) * 100< 20%
Alert Volume Reduction(Old Volume - New Volume) / Old Volume * 10030-50% per quarter
Mean Triage TimeTotal triage time / Total alerts< 8 minutes
Rule PrecisionTP / (TP + FP)> 0.80
Analyst SatisfactionSurvey score> 4/5

References

© mukul975, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 7 other files (scripts, references, assets) in skills/performing-false-positive-reduction-in-siem of mukul975/Anthropic-Cybersecurity-Skills.

  • SKILL.md
  • LICENSE
  • assets/template.md
  • references/api-reference.md
  • references/standards.md
  • references/workflows.md
  • scripts/agent.py
  • scripts/process.py

Open the folder on GitHubat commit 54a7988

Compare with similar skills

Performing False Positive Reduction In Siem next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Performing False Positive Reduction In Siem compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Performing False Positive Reduction In Siem this skillmukul975/Anthropic-Cybersecurity-Skills34k—~1.9kAutomated safety check: PassApache-2.0
Threat Intelligence OSINTzhaoxuya520/reverse-skill41k1 repos~1kAutomated safety check: PassMIT
Enrich Iocdandye/ai-runbooks127—~702Automated safety check: PassApache-2.0
Secops Detection Engineeringgoogle/skills21k1 repos~4.8kAutomated safety check: PassApache-2.0
Malware Analystaiskillstore/marketplace4336 repos~1.7kAutomated safety check: PassNone
Detection Engineering Coverage Evaluationgoogle/skills21k—~3.3kAutomated safety check: PassApache-2.0

Similar skills

  • Threat Intelligence OSINT

    zhaoxuya520/reverse-skill

    Enriches IOCs, campaigns, impersonation and scams from public sources, including bounded X search through Xquik, and checks each lead against independent evidence.

    41k GitHub starsUsed in 1 repo~1k tokens
    SecurityAuto-check passed
  • Enrich Ioc

    dandye/ai-runbooks

    Enrich an IOC (IP, domain, hash, URL) with threat intelligence.

    127 GitHub stars~702 tokensUpdated 1 mo ago
    SecurityAuto-check passed
  • Official

    Author, validate, test, and deploy YARA-L 2.0 detection rules and evaluate end-to-end detection coverage gaps in Google SecOps.

    21k GitHub starsUsed in 1 repo~4.8k tokens
    SecurityAuto-check passed
  • Malware Analyst

    aiskillstore/marketplace

    Expert malware analyst specializing in defensive malware research, threat intelligence, and incident response.

    433 GitHub starsUsed in 6 repos~1.7k tokens
    SecurityAuto-check passed
  • Automates the end-to-end detection engineering workflow in Google SecOps using MCP tools.

    21k GitHub stars~3.3k tokensUpdated yesterday
    SecurityAuto-check passed
  • Hunt Threat

    dandye/ai-runbooks

    Conduct proactive, hypothesis-driven threat hunting. An agent skill from dandye/ai-runbooks.

    127 GitHub stars~1.4k tokensUpdated 1 mo ago
    SecurityAuto-check passed

More from mukul975/Anthropic-Cybersecurity-Skills

All 644 skills in this repo
  • Campaign Attribution Evidence Analysis

    mukul975/Anthropic-Cybersecurity-Skills

    Weighs infrastructure, TTP, malware code and timing evidence with the Diamond Model and competing hypotheses to reach a confidence-rated attribution.

    34k GitHub stars~2.3k tokensUpdated 1 mo ago
    Auto-check passed
  • Go Malware Analysis in Ghidra

    mukul975/Anthropic-Cybersecurity-Skills

    Walks through reverse engineering Go-compiled malware in Ghidra: parsing buildinfo and pclntab, recovering stripped function names and extracting dependencies.

    34k GitHub stars~2.8k tokensUpdated 1 mo ago
    Auto-check passed
  • LNK and Jump List Forensics

    mukul975/Anthropic-Cybersecurity-Skills

    Guides forensic analysis of Windows LNK shortcut files and Jump Lists with LECmd, JLECmd and manual parsing to show file access and program execution.

    34k GitHub stars~2.8k tokensUpdated 1 mo ago
    Auto-check passed
  • Malware Persistence Analysis with Autoruns

    mukul975/Anthropic-Cybersecurity-Skills

    Hunts Windows malware persistence with Sysinternals Autoruns, covering run keys, services, scheduled tasks and drivers, with baseline comparison.

    34k GitHub stars~1.2k tokensUpdated 1 mo ago
    Auto-check passed
  • NTFS MFT Deleted File Recovery

    mukul975/Anthropic-Cybersecurity-Skills

    Guides a Windows forensic examination of the NTFS Master File Table to recover deleted-file evidence, build timelines and spot timestomping.

    34k GitHub stars~2.7k tokensUpdated 1 mo ago
    Auto-check passed
  • Network Covert Channel Analysis

    mukul975/Anthropic-Cybersecurity-Skills

    Detects DNS tunneling, ICMP exfiltration and HTTP-based covert channels in packet captures and DNS logs when hunting for hidden command-and-control traffic.

    34k GitHub stars~2k tokensUpdated 1 mo ago
    Auto-check passed

Categories

Questions about Performing False Positive Reduction In Siem

What does Performing False Positive Reduction In Siem do?

Reduces SIEM false positives through systematic rule tuning, threshold adjustment, correlation logic refinement, allowlisting, and threat intelligence enrichment. Performing False Positive Reduction In Siem is an agent skill from mukul975/Anthropic-Cybersecurity-Skills. Reduces SIEM false positives through systematic rule tuning, threshold adjustment, correlation logic refinement, allowlisting, and threat intelligence enrichment.

When should I use Performing False Positive Reduction In Siem?

Performing False Positive Reduction In Siem fits situations like: SOC analysts are overwhelmed by alert noise; tuning noisy detection rules; during a quarterly SIEM rule review to cut alert fatigue.

How do I install Performing False Positive Reduction In Siem in Claude Code?

Run `npx skills add mukul975/Anthropic-Cybersecurity-Skills --skill performing-false-positive-reduction-in-siem -a claude-code`. Or copy the skill folder (skills/performing-false-positive-reduction-in-siem in mukul975/Anthropic-Cybersecurity-Skills) into .claude/skills/performing-false-positive-reduction-in-siem in your project. Claude Code loads it when a task matches its description.

How do I install Performing False Positive Reduction In Siem in Codex?

Run `npx skills add mukul975/Anthropic-Cybersecurity-Skills --skill performing-false-positive-reduction-in-siem -a codex`. Or copy the skill folder (skills/performing-false-positive-reduction-in-siem in mukul975/Anthropic-Cybersecurity-Skills) into .agents/skills/performing-false-positive-reduction-in-siem in your project. Codex loads it when a task matches its description.

Can I use Performing False Positive Reduction In Siem in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add mukul975/Anthropic-Cybersecurity-Skills --skill performing-false-positive-reduction-in-siem -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/performing-false-positive-reduction-in-siem, .gemini/skills/performing-false-positive-reduction-in-siem, .github/skills/performing-false-positive-reduction-in-siem and .opencode/skills/performing-false-positive-reduction-in-siem in your project.

What does Performing False Positive Reduction In Siem need to run?

Going by SKILL.md and its folder, Performing False Positive Reduction In Siem needs Python for the scripts in its folder. Our summary lists: Python 3.

Does Performing False Positive Reduction In Siem access the network?

SKILL.md names 4 domains. As links in the text: cybersierra.co, connectwise.com, prophetsecurity.ai and manageengine.com. This is read from the text; nothing was executed.

Is Performing False Positive Reduction In Siem safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.

What licence does Performing False Positive Reduction In Siem use?

Performing False Positive Reduction In Siem is published under the Apache-2.0 licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Performing False Positive Reduction In Siem use?

About 1.9k tokens (SKILL.md is roughly 7.5k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 816 tokens, read only when the agent opens those files.

What are the alternatives to Performing False Positive Reduction In Siem?

Skills that share tags, products or a category with Performing False Positive Reduction In Siem: Threat Intelligence OSINT (zhaoxuya520/reverse-skill, 41k stars), Enrich Ioc (dandye/ai-runbooks, 127 stars), Secops Detection Engineering (google/skills, 21k stars) and Malware Analyst (aiskillstore/marketplace, 433 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Performing False Positive Reduction In Siem?

mukul975 (a GitHub user) maintains it in mukul975/Anthropic-Cybersecurity-Skills, which has 34,116 GitHub stars. The repository holds 644 skills in this directory. The repository was last updated on August 31, 2026.

Source: mukul975/Anthropic-Cybersecurity-Skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.