Detection YAML Engineer

Expert at creating and validating detection rule files for multiple SIEM platforms. Supports Splunk security_content YAML, Sigma rules, Elastic detection TOML, and KQL analytics. Ensures compliance with repository conventions and optimal query performance. Use when creating or modifying detection rules.

MHaggis Updated

File contents

MHaggis/Security-Detections-MCP/tree/main/.claude/skills/detection-yaml-engineer commit ada8f0722f

Frequently asked questions

npx skillmds@latest add mhaggis/detection-yaml-engineer