MHaggis/Security-Detections-MCP
Cursor rule Claude Code
Detection and Story creation templates for multiple SIEM platforms.
MHaggis/Security-Detections-MCP
Cursor rule Claude Code
Detection and Story creation templates for multiple SIEM platforms.
MHaggis/Security-Detections-MCP
Cursor rule Claude Code
ONLY CREATE ONE FILE when asked for threat analysis, gap analysis, or coverage reports.
MHaggis/Security-Detections-MCP
Skill Claude CodeCodex
Create grouped detection narratives that tie individual rules into coherent threat stories. Covers Splunk Analytic Stories, Elastic detection rule groups, and Sentinel analytics grouping.
MHaggis/Security-Detections-MCP
Skill Claude CodeCodex
Execute and validate adversary emulation tests using Atomic Red Team. Covers standard atomics, custom atomics (T9999.XXX), deployment workflows, and detection validation.
MHaggis/Security-Detections-MCP
Skill Claude CodeCodex
Generate MITRE ATT&CK Navigator layers for coverage visualization, threat actor mapping, and gap analysis. Produces JSON files compatible with the Navigator web app.
MHaggis/Security-Detections-MCP
Skill Claude CodeCodex
Build and manage adversary emulation lab environments for any SIEM. Covers Splunk Attack Range, Elastic Security labs, Azure Sentinel labs, and Docker-based setups. Maps data source requirements to infrastructure components.
MHaggis/Security-Detections-MCP
Skill Claude CodeCodex
Analyzes detection coverage using Sigma, Splunk, and Elastic rules. Use when checking coverage for techniques, tactics, threat actors, or generating Navigator layers from detections.
MHaggis/Security-Detections-MCP
Skill Claude CodeCodex
Expert CTI analyst specializing in detection engineering, MITRE ATT&CK mapping, behavioral analysis, and intelligence-driven detection creation. SIEM-agnostic methodology that works with Splunk SPL, KQL, Sigma, and Elastic. Use when analyzing threat reports, creating detections, mapping MITRE techniques, or developing…
MHaggis/Security-Detections-MCP
Skill Claude CodeCodex
Create, deploy, and execute custom Atomic Red Team tests (T9999.XXX series) for detection validation. Covers YAML authoring, Ansible deployment, and manual alternatives.
MHaggis/Security-Detections-MCP
Skill Claude CodeCodex
Map MITRE ATT&CK techniques to required data sources across Windows, Linux, cloud, network, and EDR telemetry. Includes CIM, ECS, Sigma, and KQL (Sentinel) field mapping comparisons.
MHaggis/Security-Detections-MCP
Skill Claude CodeCodex
Expert detection quality assurance reviewer. Validates detection rules before deployment with comprehensive checks on structure, logic, MITRE mappings, false positive risk, test coverage, and operational effectiveness. Works with SPL, KQL, Sigma, and Elastic formats. Use when reviewing detections or performing QA…
MHaggis/Security-Detections-MCP
Skill Claude CodeCodex
Expert at creating test scenarios for detections using Atomic Red Team, attack simulation tools, and validation frameworks. Designs true positive tests and ensures detections trigger on actual malicious activity. Works across SIEM platforms. Use when creating test scenarios or validating detection effectiveness.
MHaggis/Security-Detections-MCP
Skill Claude CodeCodex
Expert at creating and validating detection rule files for multiple SIEM platforms. Supports Splunk securitycontent YAML, Sigma rules, Elastic detection TOML, and KQL analytics. Ensures compliance with repository conventions and optimal query performance. Use when creating or modifying detection rules.
MHaggis/Security-Detections-MCP
Skill Claude CodeCodex
Analyze pull requests for detection coverage gaps and recommend additional detections, story alignments, and test coverage to extend PRs before merge.
MHaggis/Security-Detections-MCP
Skill Claude CodeCodex
Optimize detection queries for performance across Splunk (SPL), Microsoft Sentinel (KQL), and Elastic Security (EQL/ES|QL). Covers search pipeline internals, common anti-patterns, and optimization techniques for detection rules on each platform.
MHaggis/Security-Detections-MCP
Skill Claude CodeCodex
Analyze software supply chain attacks across package registries (npm, PyPI, RubyGems), CI/CD pipelines (GitHub Actions, GitLab CI), and container ecosystems. Includes detection engineering patterns for Splunk, Sentinel, Elastic, and Sigma.
MHaggis/Security-Detections-MCP
Skill Claude CodeCodex
Expert at analyzing unstructured threat intelligence reports (CISA alerts, vendor blogs, research papers) and extracting actionable detection logic, TTPs, behavioral indicators, and MITRE ATT&CK mappings. Focuses on behaviors over IOCs. Use when provided with threat reports, security advisories, or campaign…
MHaggis/Security-Detections-MCP
Agent Cursor
Last Updated: 2026-02-02 Source: Lotus Blossom Chrysalis Backdoor detection engineering workflow.
MHaggis/Security-Detections-MCP
Agent Cursor
Atomic Red Team testing specialist. Use when finding or executing atomic tests for detection validation.
MHaggis/Security-Detections-MCP
Agent Cursor
Attack Range configuration and build specialist. Use to build custom ranges for specific detection testing scenarios.
MHaggis/Security-Detections-MCP
Agent Cursor
Gap analysis specialist. Use to identify detection coverage gaps for threats, actors, or techniques.
MHaggis/Security-Detections-MCP
Agent Cursor
Threat intelligence specialist. Use when parsing threat reports, CISA alerts, or extracting TTPs from intelligence sources.
MHaggis/Security-Detections-MCP
Agent Cursor
Attack data export specialist. Use after successful validation to dump attack data for the attackdata repo.
MHaggis/Security-Detections-MCP
Agent Cursor
Detection writing specialist. Use when creating detection rules from techniques or threat analysis. Supports SPL, KQL, Sigma, and Elastic formats.