What problem does it solve? Turning a validated threat hunt into a production detection rule is error-prone: false positives erode analyst trust, platforms impose different mandatory columns and NRT constraints, and multi-platform deployments drift out of parity. This Skill encodes the full detection engineering lifecycle so hunts become reliable, well-documented detection rules. ## Core Features & Use Cases - Hunt-to-Rule Conversion: A 7-step process covering time-filter adjustment, required output columns, FP reduction with justified exclusions, entity mapping, conservative response actions, and NRT constraint handling. - OpenTide Lifecycle Sequencing: Governs the TVM → DOM → MDR object flow with PR scope discipline and maturity progression from THEORETICAL to tuned production rules. - Multi-Platform Parity: A capability matrix and parity checklist for Microsoft Sentinel, Defender, Splunk, CrowdStrike, SentinelOne, Carbon Black, and HarfangLab deployments. - Use Case: After validating a KQL hunt in Microsoft Sentinel, use this Skill to convert it into a scheduled analytic rule with entity mappings, documented FP exclusions, and alert-only response actions, then mirror it as a Splunk correlation search. ## Quick Start Ask the agent to convert my validated hunting query into a production detection rule for Microsoft Sentinel following the 7-step conversion process.