Skip to main content
MHaggis
Profil créateur GitHub

MHaggis

Vue par dépôt de 16 skills collectés dans 2 dépôts GitHub.

skills collectés
16
dépôts
2
mis à jour
10 avr. 2026
explorateur de dépôts

Dépôts et skills représentatifs

att-ck-navigator-layer-generator
Analystes en sécurité de l'information

Generate MITRE ATT&CK Navigator layers for coverage visualization, threat actor mapping, and gap analysis. Produces JSON files compatible with the Navigator web app.

10 avr. 2026
analytic-story-builder
Analystes en sécurité de l'information

Create grouped detection narratives that tie individual rules into coherent threat stories. Covers Splunk Analytic Stories, Elastic detection rule groups, and Sentinel analytics grouping.

5 mars 2026
atomic-red-team-testing
Analystes en sécurité de l'information

Execute and validate adversary emulation tests using Atomic Red Team. Covers standard atomics, custom atomics (T9999.XXX), deployment workflows, and detection validation.

5 mars 2026
test-environment-builder
Analystes en sécurité de l'information

Build and manage adversary emulation lab environments for any SIEM. Covers Splunk Attack Range, Elastic Security labs, Azure Sentinel labs, and Docker-based setups. Maps data source requirements to infrastructure components.

5 mars 2026
cti-detection-engineer
Analystes en sécurité de l'information

Expert CTI analyst specializing in detection engineering, MITRE ATT&CK mapping, behavioral analysis, and intelligence-driven detection creation. SIEM-agnostic methodology that works with Splunk SPL, KQL, Sigma, and Elastic. Use when analyzing threat reports,…

5 mars 2026
custom-atomics-deployment
Analystes en sécurité de l'information

Create, deploy, and execute custom Atomic Red Team tests (T9999.XXX series) for detection validation. Covers YAML authoring, Ansible deployment, and manual alternatives.

5 mars 2026
data-source-mapper
Analystes en sécurité de l'information

Map MITRE ATT&CK techniques to required data sources across Windows, Linux, cloud, network, and EDR telemetry. Includes CIM, ECS, Sigma, and KQL (Sentinel) field mapping comparisons.

5 mars 2026
detection-reviewer
Analystes en sécurité de l'information

Expert detection quality assurance reviewer. Validates detection rules before deployment with comprehensive checks on structure, logic, MITRE mappings, false positive risk, test coverage, and operational effectiveness. Works with SPL, KQL, Sigma, and Elastic…

5 mars 2026
Affichage de 8 skills collectés sur 15.
2 dépôts affichés sur 2
Tous les dépôts sont affichés