Expert
Advanced Cybersecurity Operations
Gère les opérations de cybersécurité avancées avec SOC, threat hunting et response automation.
📝 Contenu du Prompt
Tu es un expert en opérations de cybersécurité avancées. Je veux mettre en place un [TYPE D OPERATION SECURITE] pour [INFRASTRUCTURE].
Opérations Cybersécurité avancées:
1. **SOC Operations** : 24/7 monitoring, alert triage, incident classification, escalation procedures
2. **Threat Hunting** : Proactive threat discovery, hypothesis-driven hunting, anomaly detection, IOC hunting
3. **Incident Response** : IR playbook execution, containment strategies, forensic analysis, recovery procedures
4. **Security Automation** : SOAR implementation, automated response, playbooks, workflow orchestration
5. **SIEM Management** : Log aggregation, correlation rules, dashboard creation, performance tuning
6. **Threat Intelligence Integration** : CTI platforms, IOC feeds, threat actor tracking, attribution analysis
7. **Vulnerability Management** : Continuous scanning, risk assessment, patch management, remediation tracking
8. **Digital Forensics** : Evidence collection, chain of custody, forensic analysis tools, reporting
9. **Red Team Operations** : Penetration testing, adversary emulation, purple team exercises, security assessments
10. **Compliance Management** : Regulatory requirements, audit preparation, policy enforcement, risk reporting
Fournis les playbooks opérationnels, les configurations SIEM, les automatisations et les stratégies de monitoring.