Skip to main content
Run any Skill in Manus
with one click
OpenTideHQ
GitHub creator profile

OpenTideHQ

Repository-level view of 27 collected skills across 1 GitHub repositories.

skills collected
27
repositories
1
updated
2026-06-24
repository map

Where the skills live

Top repositories by collected skill count, with their share of this creator catalog and occupation spread.

repository explorer

Repositories and representative skills

splunk-spl-processing
information-security-analysts

Splunk Enterprise and Enterprise Security SPL authoring for detection engineering — index/sourcetype/time discipline, tstats/CIM acceleration, ESCU macro layers, ES correlation searches, notables, and RBA. Use when authoring or reviewing SPL, configurations.splunk MDR blocks, ES correlation searches, or translating KQL hypotheses to Splunk. Pair with detection-engineering and opentide-detection-rule.

2026-06-24
harfanglab
information-security-analysts

HarfangLab orb / EDR detection engineering — Sigma rule authoring in CoreTide's validated YAML schema (selections array, modifiers, conditional field validation), RHQL hunt query language, YARA file/memory scanning (CoreTide structure with imports, meta.context, auto-routing), full logsource category catalogue (39 Windows, 12 Linux, 6 macOS), 21 Sigma modifiers, maturity/confidence/action lifecycle, exclusion discipline, and SIEM ingestion patterns. Distilled from CoreTide HarfangLab sub-schema and SigmaHQ (3132 rules). Use for harfanglab-keyed configurations in OpenTide MDR objects.

2026-05-01
sentinelone-singularity
information-security-analysts

SentinelOne Singularity detection engineering — explicit distinction from Microsoft Sentinel, surface map across STAR Custom Logic (sensor-side behavioural rules), Deep Visibility (DVQL), Singularity Data Lake / PowerQuery (SDL alert configuration, scheduled queries, geo/math functions), exclusions and policies, Storyline ID-based correlation, AI Engine policy modes (detect / protect), SIEM ingestion patterns, and entity alignment for cross-platform correlation. Distilled from Sentinel-One/ai-siem community detection library. Use for sentinel_one-keyed configurations in OpenTide MDR objects — never confuse with microsoft-sentinel.

2026-05-01
crowdstrike-falcon
information-security-analysts

CrowdStrike Falcon detection engineering — distinguishes Falcon Insight (Event Search / EAM) from Falcon Next-Gen SIEM (LogScale / CQL), covers Falcon Query Language idioms, Custom IOA / IOC discipline, Correlation Rules (detection-as-code), Falcon Fusion workflow automation, sensor coverage gaps across Windows / macOS / Linux, SIEM ingestion patterns, real-time response guardrails, and entity-identifier alignment for cross-platform correlation. Distilled from CrowdStrike/falconpy SDK samples and API documentation. Use when authoring or reviewing CrowdStrike-keyed configurations in OpenTide MDR objects.

2026-05-01
carbon-black-cloud
information-security-analysts

VMware Carbon Black Cloud Enterprise EDR authoring guidance — distinguishes process search query syntax (CBC search language) from watchlist feeds, scheduled searches, and live response. Covers indicator vs IOC discipline, watchlist subscription model, alert override / interrupt, sensor capability boundaries, and entity identifier alignment for cross-platform correlation. Use for carbon_black_cloud-keyed configurations in OpenTide MDR objects.

2026-05-01
mitre-attack
information-security-analysts

MITRE ATT&CK mapping discipline and technique reference for OpenTide TVM, DOM, and MDR objects — technique vs sub-technique selection, tactic assignment, multi-technique chaining, version pinning, revocation handling, coverage gap analysis, platform matrix awareness, and a locally searchable technique index. Use when populating threat.att&ck fields in TVMs, mapping DOM signals to techniques, tagging MDR rules, assessing detection coverage against the ATT&CK matrix, or looking up technique IDs and descriptions.

2026-05-01
kusto-query-language
software-developers

Platform-agnostic Kusto Query Language (KQL) patterns, optimisation rules, anti-patterns, and correlation techniques shared by Microsoft Sentinel and Microsoft Defender Advanced Hunting. Covers operator hierarchy, filter ordering, joins, summarise patterns, commenting discipline, false-positive engineering, IOC templates, and bug-class anti-patterns. Use when authoring or reviewing any KQL — pair with microsoft-sentinel or microsoft-defender-endpoint for table schemas, ingestion semantics, and platform-native rule constraints.

2026-04-30
windows-event-logs
information-security-analysts

Windows native event log authoring guidance for detection engineering — Security, Sysmon, PowerShell, and system event channels. Covers critical Event IDs (4624/4625/4688/4697/4720/5140/7045), Sysmon EID 1-29 with configuration discipline, PowerShell ScriptBlock/Module logging, EVTX channel routing, audit policy prerequisites, ETW fundamentals, and SIEM ingestion patterns. Use when authoring detections that depend on native Windows telemetry, configuring audit policies for detection coverage, or bridging Windows events to platform-specific query skills.

2026-04-30
Showing top 8 of 27 collected skills in this repository.
Showing 1 of 1 repositories
All repositories loaded