detection-engineering skills

145 tagged detection-engineering, measured the same way as everything else here.

Browse within: mitre-attack 60dfir 59malware-analysis 58reverse-engineering 58detection-as-code 26cybersecurity 24blue-team 23detection-rules 23fastapi 23malware 7deobfuscation 6document-malware 6static-analysis 6c2 5

MHaggis/Security-Detections-MCP

Skill Claude CodeCodex

Execute and validate adversary emulation tests using Atomic Red Team. Covers standard atomics, custom atomics (T9999.XXX), deployment workflows, and detection validation.

478 2mo ago A 40 tokens

MHaggis/Security-Detections-MCP

Skill Claude CodeCodex

Build and manage adversary emulation lab environments for any SIEM. Covers Splunk Attack Range, Elastic Security labs, Azure Sentinel labs, and Docker-based setups. Maps data source requirements to infrastructure components.

478 2mo ago A 45 tokens

MHaggis/Security-Detections-MCP

Skill Claude CodeCodex

Optimize detection queries for performance across Splunk (SPL), Microsoft Sentinel (KQL), and Elastic Security (EQL/ES|QL). Covers search pipeline internals, common anti-patterns, and optimization techniques for detection rules on each platform.

478 2mo ago A 55 tokens

thrunt-debug

06

backbay-labs/thrunt-god

Skill Claude CodeCodex

Systematic debugging with persistent state across context resets.

36 1mo ago A 13 tokens original MIT

depalmar/ai-dfir-toolkit

Skill Claude CodeCodex

Research, author, and validate AI agent artifact catalog entries documenting the forensic artifacts AI agents leave on endpoints - install paths, config and credential files, MCP server configs, listening ports, process trees, registry keys, and the Windows event log records that prove a tool ran. Use this skill…

23 12d ago A 197 tokens original Apache-2.0

meltedinhex/analyst-ai-pack

Skill Claude CodeCodex

Analyzes Windows Authenticode signatures on PE files: checking for a signature, reading the signer certificate chain, detecting revoked/expired/stolen certs, and recognizing signature-stripping and catalog-signing abuse. Activates for requests to analyze a code signature, verify Authenticode, or assess signer trust on…

22 1mo ago A 74 tokens original Apache-2.0

meltedinhex/analyst-ai-pack

Skill Claude CodeCodex

Statically analyzes Linux ELF malware: ELF header and sections, dynamic symbols and imports, segment permissions, embedded strings, and packing indicators to infer capability without execution. Activates for requests to analyze an ELF binary, Linux malware, or shared object.

22 1mo ago A 59 tokens original Apache-2.0

meltedinhex/analyst-ai-pack

Skill Claude CodeCodex

Analyzes weaponized Windows shortcut (.lnk) files: parsing the shell link structure for the target command, arguments, icon, and working directory, and recovering hidden PowerShell/cmd payloads and embedded content used in phishing. Activates for requests to analyze a malicious LNK, parse a shortcut file, or extract a…

22 1mo ago A 81 tokens original Apache-2.0

dfirtnt/Huntable-CTI-Studio

Skill Claude CodeCodex

Add a new extraction sub-agent to Huntable CTI Studio as a first-class peer of CmdlineExtract, ProcTreeExtract, HuntQueriesExtract, RegistryExtract, ServicesExtract, and ScheduledTasksExtract. Use this skill whenever the user asks to "add a new agent", "create a sub-agent", "wire up a new extractor", "add a new…

11 5d ago A 129 tokens original MIT

cut-release

12

dfirtnt/Huntable-CTI-Studio

Skill Claude CodeCodex

Interactive walkthrough for cutting a new release of Huntable CTI Studio. Use this skill whenever the user says "cut a release", "ship a release", "tag a version", "bump the version", "new release", "do the release", "release vX.Y.Z", "ship v5.4.0", "time to release", or otherwise signals they want to move code from…

11 5d ago A 136 tokens original MIT

dfirtnt/Huntable-CTI-Studio

Skill Claude CodeCodexCursor

Audit test coverage gaps and generate unit tests to close them. Use when the user says "test trueup", "coverage gaps", "test coverage audit", "fill coverage", "write missing tests", "backfill tests", "scope tests", "test what I changed", or any request to identify and fill test gaps. Three modes: audit (report only)…

11 5d ago A 96 tokens original MIT

gauntlet-loop

14

trilwu/gauntlet-loop-skills

Skill Claude CodeCodex

Part of gauntlet-loop

Domain-agnostic method for producing top-tier work with the Gauntlet Loop — split → build → blind-critic → repeat — against a hard "bar" the agent cannot argue its way around. A lead splits a goal into independently gradeable parts; each part gets a specialist builder plus a ruthless blind critic (clean context) who…

3 1mo ago A 227 tokens original MIT

trilwu/gauntlet-loop-skills

Skill Claude CodeCodex

Part of gauntlet-loop

Apply the Gauntlet Loop to security vulnerability hunting — a hunter (builder) proposes candidate vulnerabilities and a blind validator (critic) inspects the real artifact and MUST build a working non-destructive PoC before anything is confirmed. The bar is exploitability + CWE mapping + real vulnerability-class…

3 1mo ago A 196 tokens original MIT

sigma-rule-reviewer

16

WRG-11/wrg-sigma-rules

Skill Claude CodeCodex

Part of wrg-sigma-rules

Review an existing sigma rule for spec compliance, detection quality, and improvement opportunities. Use when the user pastes a sigma YAML rule, asks "is this rule any good", asks for a code review on a detection, or wants to harden a rule against false positives. Runs pySigma validation, best-practices linter, and…

2 10d ago A 83 tokens original MIT

sigma-rule-writer

17

WRG-11/wrg-sigma-rules

Skill Claude CodeCodex

Part of wrg-sigma-rules

Guided sigma detection rule writing from a natural language threat description. Use when the user asks to write a sigma rule, SIEM detection rule, EDR alert logic, or any "detect when X happens" question. Asks clarifying questions (logsource, MITRE ATT&CK TTP, severity), drafts YAML via…

2 10d ago A 118 tokens original MIT

WRG-11/wrg-sigma-rules

Skill Claude CodeCodex

Part of wrg-sigma-rules

Analyze a sigma rule corpus against the MITRE ATT&CK matrix and produce a coverage gap report. Use when the user asks "what TTPs am I missing", asks for a coverage report, wants to compare their detections against a threat actor profile (e.g. APT29, Scattered Spider), or wants a prioritized list of detection rules to…

2 10d ago A 139 tokens original MIT

threadlinqs-cmd/intelthreadlinqs-mcp

Skill Claude CodeCodex

Operate the Threadlinqs Intelligence MCP server — 73 threat-intelligence tools covering threats, detection rules in Splunk SPL / Microsoft KQL / Sigma, IOCs, threat actors, CVE/CWE enrichment, MITRE ATT&CK coverage and prediction, C2 infrastructure, the correlation graph, and STIX 2.1 / ATT&CK Navigator export. Use…

0 10d ago A 285 tokens original MIT

At most 3 mods per repository are shown here, and a mod shipped inside a plugin is left to that plugin's page — the rest are on their repository pages: