Detection Engineering

Design, write, test, tune, deploy, and review detection rules through their full lifecycle, with Sigma as the canonical rule format and conversion to Splunk SPL, Sentinel/Defender KQL, Elastic EQL/ES|QL, or Chronicle YARA-L. Use it whenever someone wants to "write a detection", "build a rule for", "alert on", "turn this report/hunt/purple-team gap into a detection", "review this Sigma rule", "why is this rule so noisy", "tune the false positives", "map this rule to ATT&CK", or pastes a Sigma/KQL/SPL rule and asks whether it is any good. Also use it when a threat report, an incident lesson, or a hunt result implies a detection that nobody has written yet, even if the user only asks "how would we catch this next time".

ftrout Updated

File contents

ftrout/secops-claude-skills/tree/main/skills/detection-engineering commit 76fb0b1f23

Frequently asked questions

npx skillmds@latest add ftrout/detection-engineering