Connecting the Clues: Building a Cross-SIEM Investigation Framework with Claude Code
中文摘要
使用 Claude Code 构建跨 SIEM 调查框架,实现 Splunk 与 Azure Data Explorer 中 Windows Sysmon 及 AWS CloudTrail 事件的关联分析。
English Summary
A cross-SIEM investigation framework built with Claude Code to correlate Windows Sysmon and AWS CloudTrail events across Splunk and Azure Data Explorer.
Original Excerpt
How I designed a reusable workflow for correlating Windows Sysmon activity with AWS CloudTrail events across Splunk and Azure Data Explorer Continue reading on Medium »