← all publishers

iimp0ster

@iimp0ster source repo

10 published skills

  1. Mapping Data Sources · iimp0ster
    Maps detection requirements to concrete data sources and field-level telemetry. Produces a prioritized data source list, field mapping table, visibility gap analysis, and logging configuration requirements. Use after a detection objective is defined to determine what logs and fields the detection logic will depend on.
    0 installs
  2. Analyzing Coverage Gaps · iimp0ster
    Analyzing Coverage Gaps
    0 installs
  3. Designing Detection Logic · iimp0ster
    Designing Detection Logic
    0 installs
  4. Researching Threat Context · iimp0ster
    Researching Threat Context
    0 installs
  5. Planning Validation Testing · iimp0ster
    Designs a comprehensive testing approach to validate detection effectiveness. Produces positive and negative test procedures, an evaluation metrics framework, an Atomic Red Team test plan, and an iterative tuning strategy. Use after detection logic is designed to plan how to verify the detection fires correctly and doesn't produce excessive false positives.
    0 installs
  6. Defining Detection Objective · iimp0ster
    Translates threat research into an actionable detection goal with clear scope boundaries. Defines detection hypothesis, noise tolerance targets, success criteria, and benign behavior exclusions. Use after threat research is complete to establish what the detection will alert on and what it will exclude before designing logic.
    0 installs
  7. Generating Emulation Scripts · iimp0ster
    Generating Emulation Scripts
    0 installs
  8. Ingesting Threat Intelligence · iimp0ster
    Ingesting Threat Intelligence
    0 installs
  9. Assembling Detection Blueprint · iimp0ster
    Assembles all prior detection engineering outputs into a single deployment-ready detection blueprint document. Combines threat context, detection logic, data requirements, validation procedures, response guidance, and metadata into a structured markdown package. Use as the final step after skills 1-5 are complete to produce a shareable detection artifact.
    0 installs
  10. Profiling Environment Baseline · iimp0ster
    Documents organization-specific data schemas, tooling inventory, and known-noisy infrastructure to pre-tune detections for a specific environment. Produces a reusable exclusion baseline, data schema reference, and environment-specific tuning parameters. Use before detection logic design when the environment has unique configurations, known scanners, or specific field naming conventions.
    0 installs