detection-engineer
SolidCreate detection rules and hunting queries from malware analysis findings. Use when you need to write Sigma rules for SIEM, Suricata rules for network IDS, defang IOCs for safe sharing, or convert analysis findings into actionable detection content for SOC teams and threat hunters.
Install
Quality Score: 83/100
Skill Content
Details
- Author
- gl0bal01
- Repository
- gl0bal01/malware-analysis-claude-skills
- Created
- 10 months ago
- Last Updated
- 5 days ago
- Language
- Python
- License
- MIT
Similar Skills
Semantically similar based on skill content — not just same category
linmas-detection-rules-engineer
Detection rules engineering skill for SIEM logic, alert design, telemetry mapping, tuning, and false-positive reduction.
defense-detection-sigma
Write portable detections as Sigma rules and map them to MITRE ATT&CK, then convert to your SIEM. Load for blue-team/detection-engineering tasks: "write a detection", "sigma rule", "alert on", turning an offensive technique or an incident into a repeatable detection.
detection-engineering
Detection rule development standards. Activate when: - Writing, creating, or modifying Sigma/YARA rules - Reviewing detection rules for quality or completeness - Discussing detection coverage, gaps, or improvements - Working with YAML files containing detection logic - Asked to validate, check, or audit detection rules - Converting detections between formats (Sigma to KQL, SPL, etc.)