CtrlK
BlogDocsLog inGet started
Tessl Logo

analyzing-windows-event-logs-in-splunk

Analyzes Windows Security, System, and Sysmon event logs in Splunk to detect authentication attacks, privilege escalation, persistence mechanisms, and lateral movement using SPL queries mapped to MITRE ATT&CK techniques. Use when SOC analysts need to investigate Windows-based threats, build detection queries, or perform forensic timeline analysis of Windows endpoints and domain controllers.

72

Quality

89%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

Passed

No findings from the security scan

SKILL.md
Quality
Evals
Security

Quality

Content

78%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

The body is highly actionable with well-sequenced detection queries, but it over-inlines reference-style material and fails to point at the provided bundle files, hurting progressive disclosure.

Suggestions

Replace the inlined windows_eventcode_lookup CSV and the full Output Format example with a one-line pointer to references/api-reference.md (which already holds the event-ID tables).

Add a 'Tools & Systems' or 'Automation' pointer to scripts/agent.py so the executable Splunk SDK agent is discoverable from the skill body.

Add brief validation/tuning checkpoints (e.g., 'confirm query returns expected volume before alerting') to lift workflow clarity from 4 to 5.

DimensionReasoningScore

Conciseness

Mostly efficient with executable SPL, but the Key Concepts table, Tools & Systems list, and a full illustrative Output Format example restate domain knowledge and add tokens that could be trimmed; not a 5.

4 / 5

Actionability

Provides multiple complete, copy-paste-ready SPL queries with concrete thresholds and EventCodes mapped to ATT&CK, covering the common detection cases — matching the score-5 anchor.

5 / 5

Workflow Clarity

Six steps are clearly sequenced by attack stage; no explicit verify/tune checkpoints, but operations are read-only detection so the destructive-batch cap does not apply. Minor validation gaps keep it at 4 rather than 5.

4 / 5

Progressive Disclosure

Good section structure, but the body inlines a 12-row lookup CSV and a 20-line example output that belong in references, and never links to the existing references/api-reference.md or scripts/agent.py bundle files — references present but not signaled, matching the score-3 anchor.

3 / 5

Total

16

/

20

Passed

Description

100%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

The description is third person, concrete, and answers both what and when with natural trigger phrasing. It is a strong, low-conflict description with no padding.

DimensionReasoningScore

Specificity

Lists multiple concrete actions ('detect authentication attacks, privilege escalation, persistence mechanisms, and lateral movement using SPL queries mapped to MITRE ATT&CK techniques') with comprehensive coverage, matching the score-5 anchor.

5 / 5

Completeness

Explicitly answers 'what' (analyzes event logs to detect attacks via SPL mapped to ATT&CK) and 'when' ('Use when SOC analysts need to investigate Windows-based threats, build detection queries, or perform forensic timeline analysis'), matching the score-5 anchor.

5 / 5

Trigger Term Quality

Natural SOC vocabulary ('Windows event logs', 'Splunk', 'SOC analysts', 'MITRE ATT&CK', 'forensic timeline', 'Windows endpoints and domain controllers') covers the phrases a user would actually say, including synonyms.

5 / 5

Distinctiveness Conflict Risk

Occupies a clear niche (Windows event logs in Splunk via SPL for SOC investigation) with distinct triggers and minimal overlap with other skills.

5 / 5

Total

20

/

20

Passed

Validation

93%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation15 / 16 Passed

Validation for skill structure

CriteriaDescriptionResult

frontmatter_unknown_keys

Unknown frontmatter key(s) found; consider removing or moving to metadata

Warning

Total

15

/

16

Passed

Repository
mukul975/Anthropic-Cybersecurity-Skills
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.