threadlinqs-cmd/Threadlinqs-Security-Detection-MCP
Agent Cursor
Last Updated: 2026-02-02 Source: Lotus Blossom Chrysalis Backdoor detection engineering workflow.
threadlinqs-cmd/Threadlinqs-Security-Detection-MCP
Agent Cursor
Last Updated: 2026-02-02 Source: Lotus Blossom Chrysalis Backdoor detection engineering workflow.
threadlinqs-cmd/Threadlinqs-Security-Detection-MCP
Agent Cursor
Atomic Red Team testing specialist. Use when finding or executing atomic tests for detection validation.
threadlinqs-cmd/Threadlinqs-Security-Detection-MCP
Agent Cursor
Attack Range configuration and build specialist. Use to build custom ranges for specific detection testing scenarios.
threadlinqs-cmd/Threadlinqs-Security-Detection-MCP
Agent Cursor
Gap analysis specialist. Use to identify detection coverage gaps for threats, actors, or techniques.
threadlinqs-cmd/Threadlinqs-Security-Detection-MCP
Agent Cursor
Threat intelligence specialist. Use when parsing threat reports, CISA alerts, or extracting TTPs from intelligence sources.
threadlinqs-cmd/Threadlinqs-Security-Detection-MCP
Agent Cursor
Attack data export specialist. Use after successful validation to dump attack data for the attackdata repo.
threadlinqs-cmd/Threadlinqs-Security-Detection-MCP
Agent Cursor
Detection writing specialist. Use when creating detection rules from techniques or threat analysis. Supports SPL, KQL, Sigma, and Elastic formats.
threadlinqs-cmd/Threadlinqs-Security-Detection-MCP
Agent Cursor
False positive analyst. Use to assess FP risk before staging detections.
threadlinqs-cmd/Threadlinqs-Security-Detection-MCP
Agent Cursor
Main workflow coordinator for the threat-to-detection pipeline.
threadlinqs-cmd/Threadlinqs-Security-Detection-MCP
Agent Cursor
Reviews open PRs, validates content quality, identifies gaps, and adds improvements. Use to enhance existing PRs before merge.
threadlinqs-cmd/Threadlinqs-Security-Detection-MCP
Agent Cursor
GitHub PR specialist. Use to stage DRAFT PRs to detection and attackdata repos. NEVER auto-merge.
threadlinqs-cmd/Threadlinqs-Security-Detection-MCP
Agent Cursor
Quality assurance specialist. Use to review detection quality before PR staging.
threadlinqs-cmd/Threadlinqs-Security-Detection-MCP
Agent Cursor
Detection validation specialist. Use after atomic execution to verify detections fire correctly in any SIEM.
threadlinqs-cmd/Threadlinqs-Security-Detection-MCP
Agent Cursor
Splunk-specific detection validator. Use after atomic execution to verify SPL detections fire correctly in Splunk. For other SIEMs, use /siem-validator instead.
threadlinqs-cmd/Threadlinqs-Security-Detection-MCP
Agent Cursor
Skeptical validator. Use after detection workflow claims completion to verify work actually done.
threadlinqs-cmd/Threadlinqs-Security-Detection-MCP
Cursor rule Cursor
Cursor rule "contentctl-path" from threadlinqs-cmd/Threadlinqs-Security-Detection-MCP, covering contentctl tool configuration (splunk-specific), location, pip install requirements, option 1: force reinstall and option 2: direct pypi url.
threadlinqs-cmd/Threadlinqs-Security-Detection-MCP
Cursor rule Cursor
The tests: section MUST have valid URLs, NOT placeholder descriptions.
threadlinqs-cmd/Threadlinqs-Security-Detection-MCP
Cursor rule Cursor
Linux detection testing workflow and lessons learned.
threadlinqs-cmd/Threadlinqs-Security-Detection-MCP
Cursor rule Cursor
Any pip install command MUST include one of these options.
threadlinqs-cmd/Threadlinqs-Security-Detection-MCP
Cursor rule Cursor
Self-healing behavior - automatically fix errors and continue.
threadlinqs-cmd/Threadlinqs-Security-Detection-MCP
Cursor rule Cursor
Detection validation tools - location, usage, and multi-SIEM support.
threadlinqs-cmd/Threadlinqs-Security-Detection-MCP
MCP server Claude CodeCodexCursor
Advanced MCP server for security detections with Detection Engineering Intelligence, Knowledge Graph (Tribal Knowledge), Elicitation, and Resource Subscriptions. Runs locally from the security-detections-mcp npm package. Needs 5 environment variables to run.
threadlinqs-cmd/intelthreadlinqs-mcp
Plugin Claude Code
Curated cyber-threat intelligence in Claude — 81 read-only tools across threats, SPL/KQL/Sigma detections, IOCs, MITRE ATT&CK, CVE/CWE, C2 infrastructure, and threat-actor attribution. Purple/Gold tier.
threadlinqs-cmd/intelthreadlinqs-mcp
MCP server Claude CodeCodexCursor +2
MCP server for Threadlinqs Intelligence Platform — 81 tools, 25 prompts and 14 resources across threat intel, detections, IOCs, actors, C2, MITRE chains, correlations and Purple-tier composite intelligence. Runs locally from the intelthreadlinqs-mcp npm package. Needs 1 environment variable to run.