threadlinqs-cmd/Threadlinqs-Security-Detection-MCP
Agent Cursor
Last Updated: 2026-02-02 Source: Lotus Blossom Chrysalis Backdoor detection engineering workflow.
Unified Detection Engineering Platform — 7,283+ detections across Sigma, Splunk ESCU, Elastic & KQL, powered by MCP
threadlinqs-cmd/Threadlinqs-Security-Detection-MCP
Agent Cursor
Last Updated: 2026-02-02 Source: Lotus Blossom Chrysalis Backdoor detection engineering workflow.
threadlinqs-cmd/Threadlinqs-Security-Detection-MCP
Agent Cursor
Atomic Red Team testing specialist. Use when finding or executing atomic tests for detection validation.
threadlinqs-cmd/Threadlinqs-Security-Detection-MCP
Agent Cursor
Attack Range configuration and build specialist. Use to build custom ranges for specific detection testing scenarios.
threadlinqs-cmd/Threadlinqs-Security-Detection-MCP
Agent Cursor
Gap analysis specialist. Use to identify detection coverage gaps for threats, actors, or techniques.
threadlinqs-cmd/Threadlinqs-Security-Detection-MCP
Agent Cursor
Threat intelligence specialist. Use when parsing threat reports, CISA alerts, or extracting TTPs from intelligence sources.
threadlinqs-cmd/Threadlinqs-Security-Detection-MCP
Agent Cursor
Attack data export specialist. Use after successful validation to dump attack data for the attackdata repo.
threadlinqs-cmd/Threadlinqs-Security-Detection-MCP
Agent Cursor
Detection writing specialist. Use when creating detection rules from techniques or threat analysis. Supports SPL, KQL, Sigma, and Elastic formats.
threadlinqs-cmd/Threadlinqs-Security-Detection-MCP
Agent Cursor
False positive analyst. Use to assess FP risk before staging detections.
threadlinqs-cmd/Threadlinqs-Security-Detection-MCP
Agent Cursor
Main workflow coordinator for the threat-to-detection pipeline.
threadlinqs-cmd/Threadlinqs-Security-Detection-MCP
Agent Cursor
Reviews open PRs, validates content quality, identifies gaps, and adds improvements. Use to enhance existing PRs before merge.
threadlinqs-cmd/Threadlinqs-Security-Detection-MCP
Agent Cursor
GitHub PR specialist. Use to stage DRAFT PRs to detection and attackdata repos. NEVER auto-merge.
threadlinqs-cmd/Threadlinqs-Security-Detection-MCP
Agent Cursor
Quality assurance specialist. Use to review detection quality before PR staging.
threadlinqs-cmd/Threadlinqs-Security-Detection-MCP
Agent Cursor
Detection validation specialist. Use after atomic execution to verify detections fire correctly in any SIEM.
threadlinqs-cmd/Threadlinqs-Security-Detection-MCP
Agent Cursor
Splunk-specific detection validator. Use after atomic execution to verify SPL detections fire correctly in Splunk. For other SIEMs, use /siem-validator instead.
threadlinqs-cmd/Threadlinqs-Security-Detection-MCP
Agent Cursor
Skeptical validator. Use after detection workflow claims completion to verify work actually done.