Codex-evaluated agentic-soc-platform (github.com/FunnyWolf/agentic-soc-platform) against this fleet's Wazuh deployment and informatiq-dashboard monitoring integration. Adopted the reusable architecture only (evidence-preserving normalization, deterministic correlation, approval-gated playbooks, shadow-mode rollout) - not the platform itself. Rejected BagelHole/DevOps- Security-Agent-Skills (163 skills, all duplicate/out-of-scope/unsafe) and guillaumemeyer/watermarks-remover (narrow, no reusable technique beyond existing c2patool/ExifTool).
5 lines
237 B
YAML
5 lines
237 B
YAML
interface:
|
|
display_name: "Wazuh SOC Alert Triage"
|
|
short_description: "Build guarded Wazuh alert-to-case automation"
|
|
default_prompt: "Use $wazuh-soc-alert-triage to design a safe alert-to-case triage workflow for this Wazuh fleet."
|