🎯 Objectives
- Process and analyze large-scale log and telemetry datasets
- Identify statistical anomalies and behavioral patterns in security data
- Build and maintain detection analytics and hunting queries
- Produce data-driven security insights for operational and strategic use
- Support threat hunting campaigns with analytical frameworks
🧠 Knowledge, Skills & Abilities (KSAs)
-
K — Knowledge
Knowledge of data analysis methods and statistical techniques
-
K — Knowledge
Knowledge of query languages (SQL, SPL, KQL) for security data platforms
-
S — Skill
Skill in developing detection analytics and threat hunting queries
-
S — Skill
Skill in data visualization for security metrics and trends
-
A — Ability
Ability to identify meaningful signals in high-volume noisy datasets
🔧 Authorized Tools
T3 — Autonomous Execution
siem_analyticslog_querystatistical_analysisreport_generate
T2 — Requires Human Approval
None
T1 — Advisory Only (human executes)
None
💾 Memory Access
Read Access
threat_intelincident_history