detection as code skills

26 tagged detection as code, measured the same way as everything else here.

Browse within: detection-engineering 26blue-team 23cybersecurity 23detection-rules 23fastapi 23

dfirtnt/Huntable-CTI-Studio

Skill Claude CodeCodex

Add a new extraction sub-agent to Huntable CTI Studio as a first-class peer of CmdlineExtract, ProcTreeExtract, HuntQueriesExtract, RegistryExtract, ServicesExtract, and ScheduledTasksExtract. Use this skill whenever the user asks to "add a new agent", "create a sub-agent", "wire up a new extractor", "add a new…

11 4d ago A 129 tokens original MIT

dfirtnt/Huntable-CTI-Studio

Skill Claude CodeCodexCursor

Audit test coverage gaps and generate unit tests to close them. Use when the user says "test trueup", "coverage gaps", "test coverage audit", "fill coverage", "write missing tests", "backfill tests", "scope tests", "test what I changed", or any request to identify and fill test gaps. Three modes: audit (report only)…

11 4d ago A 96 tokens original MIT

mdu

03

dfirtnt/Huntable-CTI-Studio

Skill Claude CodeCodexCursor

Update all Markdown documentation to reflect code and session changes. Use this skill whenever the user says "mdu", asks to "update docs", "sync documentation", "refresh changelog", "update the changelog", "docs are stale", "add this to the changelog", or any request to align documentation with recent code changes.…

11 4d ago A 203 tokens original MIT

sigma-rule-reviewer

04

WRG-11/wrg-sigma-rules

Skill Claude CodeCodex

Review an existing sigma rule for spec compliance, detection quality, and improvement opportunities. Use when the user pastes a sigma YAML rule, asks "is this rule any good", asks for a code review on a detection, or wants to harden a rule against false positives. Runs pySigma validation, best-practices linter, and…

2 9d ago A 83 tokens original MIT

sigma-rule-writer

05

WRG-11/wrg-sigma-rules

Skill Claude CodeCodex

Guided sigma detection rule writing from a natural language threat description. Use when the user asks to write a sigma rule, SIEM detection rule, EDR alert logic, or any "detect when X happens" question. Asks clarifying questions (logsource, MITRE ATT&CK TTP, severity), drafts YAML via…

2 9d ago A 118 tokens original MIT

WRG-11/wrg-sigma-rules

Skill Claude CodeCodex

Analyze a sigma rule corpus against the MITRE ATT&CK matrix and produce a coverage gap report. Use when the user asks "what TTPs am I missing", asks for a coverage report, wants to compare their detections against a threat actor profile (e.g. APT29, Scattered Spider), or wants a prioritized list of detection rules to…

2 9d ago A 139 tokens original MIT