MHaggis/Security-Detections-MCP
Skill Claude CodeCodex
Execute and validate adversary emulation tests using Atomic Red Team. Covers standard atomics, custom atomics (T9999.XXX), deployment workflows, and detection validation.
145 tagged detection-engineering, measured the same way as everything else here.
Browse within: mitre-attack 60dfir 59malware-analysis 58reverse-engineering 58detection-as-code 26cybersecurity 24blue-team 23detection-rules 23fastapi 23malware 7deobfuscation 6document-malware 6static-analysis 6c2 5
MHaggis/Security-Detections-MCP
Skill Claude CodeCodex
Execute and validate adversary emulation tests using Atomic Red Team. Covers standard atomics, custom atomics (T9999.XXX), deployment workflows, and detection validation.
MHaggis/Security-Detections-MCP
Skill Claude CodeCodex
Build and manage adversary emulation lab environments for any SIEM. Covers Splunk Attack Range, Elastic Security labs, Azure Sentinel labs, and Docker-based setups. Maps data source requirements to infrastructure components.
MHaggis/Security-Detections-MCP
Skill Claude CodeCodex
Optimize detection queries for performance across Splunk (SPL), Microsoft Sentinel (KQL), and Elastic Security (EQL/ES|QL). Covers search pipeline internals, common anti-patterns, and optimization techniques for detection rules on each platform.
Skill Claude CodeCodex
Add an idea to the backlog parking lot (999.x numbering).
Skill Claude CodeCodex
Archive completed milestone and prepare for next version.
Skill Claude CodeCodex
Systematic debugging with persistent state across context resets.
Skill Claude CodeCodex
Research, author, and validate AI agent artifact catalog entries documenting the forensic artifacts AI agents leave on endpoints - install paths, config and credential files, MCP server configs, listening ports, process trees, registry keys, and the Windows event log records that prove a tool ran. Use this skill…
Skill Claude CodeCodex
Analyzes Windows Authenticode signatures on PE files: checking for a signature, reading the signer certificate chain, detecting revoked/expired/stolen certs, and recognizing signature-stripping and catalog-signing abuse. Activates for requests to analyze a code signature, verify Authenticode, or assess signer trust on…
Skill Claude CodeCodex
Statically analyzes Linux ELF malware: ELF header and sections, dynamic symbols and imports, segment permissions, embedded strings, and packing indicators to infer capability without execution. Activates for requests to analyze an ELF binary, Linux malware, or shared object.
Skill Claude CodeCodex
Analyzes weaponized Windows shortcut (.lnk) files: parsing the shell link structure for the target command, arguments, icon, and working directory, and recovering hidden PowerShell/cmd payloads and embedded content used in phishing. Activates for requests to analyze a malicious LNK, parse a shortcut file, or extract a…
Skill Claude CodeCodex
Add a new extraction sub-agent to Huntable CTI Studio as a first-class peer of CmdlineExtract, ProcTreeExtract, HuntQueriesExtract, RegistryExtract, ServicesExtract, and ScheduledTasksExtract. Use this skill whenever the user asks to "add a new agent", "create a sub-agent", "wire up a new extractor", "add a new…
Skill Claude CodeCodex
Interactive walkthrough for cutting a new release of Huntable CTI Studio. Use this skill whenever the user says "cut a release", "ship a release", "tag a version", "bump the version", "new release", "do the release", "release vX.Y.Z", "ship v5.4.0", "time to release", or otherwise signals they want to move code from…
Skill Claude CodeCodexCursor
Audit test coverage gaps and generate unit tests to close them. Use when the user says "test trueup", "coverage gaps", "test coverage audit", "fill coverage", "write missing tests", "backfill tests", "scope tests", "test what I changed", or any request to identify and fill test gaps. Three modes: audit (report only)…
Skill Claude CodeCodex
Part of gauntlet-loop
Domain-agnostic method for producing top-tier work with the Gauntlet Loop — split → build → blind-critic → repeat — against a hard "bar" the agent cannot argue its way around. A lead splits a goal into independently gradeable parts; each part gets a specialist builder plus a ruthless blind critic (clean context) who…
Skill Claude CodeCodex
Part of gauntlet-loop
Apply the Gauntlet Loop to security vulnerability hunting — a hunter (builder) proposes candidate vulnerabilities and a blind validator (critic) inspects the real artifact and MUST build a working non-destructive PoC before anything is confirmed. The bar is exploitability + CWE mapping + real vulnerability-class…
Skill Claude CodeCodex
Part of wrg-sigma-rules
Review an existing sigma rule for spec compliance, detection quality, and improvement opportunities. Use when the user pastes a sigma YAML rule, asks "is this rule any good", asks for a code review on a detection, or wants to harden a rule against false positives. Runs pySigma validation, best-practices linter, and…
Skill Claude CodeCodex
Part of wrg-sigma-rules
Guided sigma detection rule writing from a natural language threat description. Use when the user asks to write a sigma rule, SIEM detection rule, EDR alert logic, or any "detect when X happens" question. Asks clarifying questions (logsource, MITRE ATT&CK TTP, severity), drafts YAML via…
Skill Claude CodeCodex
Part of wrg-sigma-rules
Analyze a sigma rule corpus against the MITRE ATT&CK matrix and produce a coverage gap report. Use when the user asks "what TTPs am I missing", asks for a coverage report, wants to compare their detections against a threat actor profile (e.g. APT29, Scattered Spider), or wants a prioritized list of detection rules to…
threadlinqs-cmd/intelthreadlinqs-mcp
Skill Claude CodeCodex
Operate the Threadlinqs Intelligence MCP server — 73 threat-intelligence tools covering threats, detection rules in Splunk SPL / Microsoft KQL / Sigma, IOCs, threat actors, CVE/CWE enrichment, MITRE ATT&CK coverage and prediction, C2 infrastructure, the correlation graph, and STIX 2.1 / ATT&CK Navigator export. Use…
At most 3 mods per repository are shown here, and a mod shipped inside a plugin is left to that plugin's page — the rest are on their repository pages: