threat-detection-engineer

Author Sigma detection rules with MITRE ATT&CK mapping for SIEM deployment.

1|Updated Mar 13, 2026
One-click install
npx skills add https://github.com/coreymaypray/sloth-skill-tree --skill threat-detection-engineer-coreymaypray
Or copy as Structured Prompt for Agent▼
Please help me install this Agent Skill.
Skill: threat-detection-engineer
Source: https://github.com/coreymaypray/sloth-skill-tree/tree/main/plugins/maycrest-secure/skills/threat-detection-engineer
Command: npx skills add https://github.com/coreymaypray/sloth-skill-tree --skill threat-detection-engineer-coreymaypray

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

Writes precise, low-noise detections to reduce alert fatigue and improve threat visibility across enterprise SIEMs and application telemetry.

Core Features & Use Cases

  • Sigma rule authoring with MITRE ATT&CK mapping
  • Threat hunting hypotheses and structured hunts
  • Detection-as-code pipelines with CI/CD deployment to SIEMs

Quick Start

Generate a Sigma rule to detect credential stuffing in Supabase Auth logs and validate it against sample data.

Frequently Asked Questions about threat-detection-engineer

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I write Sigma rules mapped to MITRE ATT&CK techniques?▼

Author Sigma rules by writing detection logic mapped directly to specific MITRE ATT&CK techniques, ensuring high-fidelity SIEM detections with confidence and validated threat coverage.

What is the best way to reduce SIEM alert fatigue with high-fidelity detections?▼

Reduce SIEM alert fatigue by developing precise, low-noise detections and validated playbooks that improve threat visibility across enterprise SIEMs and application telemetry.

How do I build a detection-as-code pipeline with CI/CD deployment?▼

Build detection-as-code pipelines by integrating Sigma rule authoring with CI/CD processes, enabling automated, testable, and deployable detections directly into enterprise SIEMs.

Can I generate Sigma rules to detect credential stuffing in Supabase Auth logs?▼

Generate Sigma rules to detect credential stuffing in Supabase Auth logs and validate them against sample data to ensure application-layer anomaly detection works.

How do I create threat hunting hypotheses for structured hunts?▼

Create threat hunting hypotheses by developing structured hunts driven by validated playbooks, ensuring testable and deployable detections aligned with enterprise SIEM rule development.

Does this approach work for application-layer anomaly detection in Supabase-backed apps?▼

Detection engineering works for application-layer anomaly detection in Supabase-backed apps by authoring Sigma rules and validating them against sample data for precise detections.