cti-detection-engineer

Community

Build better threat detections.

AuthorMHaggis
Version1.0.0
Installs0

System Documentation

What problem does it solve?

This Skill empowers users to create high-fidelity, intelligence-driven security detections that focus on adversary behaviors rather than easily changed indicators.

Core Features & Use Cases

  • Behavioral Analysis: Decomposes complex attacks into atomic behaviors for detection.
  • MITRE ATT&CK Mapping: Ensures detections are precisely mapped to the latest ATT&CK techniques and sub-techniques.
  • Multi-SIEM Compatibility: Generates detection logic applicable across Splunk, Sentinel, Elastic, and Sigma.
  • Use Case: Analyze a threat report, identify key adversary behaviors, map them to MITRE ATT&CK, and generate detection logic for your SIEM.

Quick Start

Use the cti-detection-engineer skill to analyze threat intelligence and generate a detection for MITRE ATT&CK technique T1003.001.

Dependency Matrix

Required Modules

None required

Components

references

💻 Claude Code Installation

Recommended: Let Claude install automatically. Simply copy and paste the text below to Claude Code.

Please help me install this Skill:
Name: cti-detection-engineer
Download link: https://github.com/MHaggis/Security-Detections-MCP/archive/main.zip#cti-detection-engineer

Please download this .zip file, extract it, and install it in the .claude/skills/ directory.
View Source Repository

Agent Skills Search Helper

Install a tiny helper to your Agent, search and equip skill from 223,000+ vetted skills library on demand.