Skip to main content

MHaggis/Security-Detections-MCP

SkillsMP는 MHaggis/Security-Detections-MCP에서 15개의 skill을 수집했습니다. skill을 열어 소스와 세부 정보를 확인하세요.

최근 기록된 소스 활동
SkillsMP 카탈로그 업데이트
수집된 skills
15
GitHub 스타
477
GitHub 포크
75

이 저장소의 skills

직업 카테고리 2개 · 100% 분류됨

수집된 skill 15개 중 15개를 표시합니다.

직업 분류
정보 보안 분석가
설명

Generate MITRE ATT&CK Navigator layers for coverage visualization, threat actor mapping, and gap analysis. Produces JSON files compatible with the Navigator web app.

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Create grouped detection narratives that tie individual rules into coherent threat stories. Covers Splunk Analytic Stories, Elastic detection rule groups, and Sentinel analytics grouping.

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Execute and validate adversary emulation tests using Atomic Red Team. Covers standard atomics, custom atomics (T9999.XXX), deployment workflows, and detection validation.

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Build and manage adversary emulation lab environments for any SIEM. Covers Splunk Attack Range, Elastic Security labs, Azure Sentinel labs, and Docker-based setups. Maps data source requirements to infrastructure components.

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Expert CTI analyst specializing in detection engineering, MITRE ATT&CK mapping, behavioral analysis, and intelligence-driven detection creation. SIEM-agnostic methodology that works with Splunk SPL, KQL, Sigma, and Elastic. Use when analyzing threat reports,…

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Create, deploy, and execute custom Atomic Red Team tests (T9999.XXX series) for detection validation. Covers YAML authoring, Ansible deployment, and manual alternatives.

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Map MITRE ATT&CK techniques to required data sources across Windows, Linux, cloud, network, and EDR telemetry. Includes CIM, ECS, Sigma, and KQL (Sentinel) field mapping comparisons.

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Expert detection quality assurance reviewer. Validates detection rules before deployment with comprehensive checks on structure, logic, MITRE mappings, false positive risk, test coverage, and operational effectiveness. Works with SPL, KQL, Sigma, and Elastic…

원문 언어: 영어

업데이트
직업 분류
소프트웨어 개발자
설명

Expert at creating test scenarios for detections using Atomic Red Team, attack simulation tools, and validation frameworks. Designs true positive tests and ensures detections trigger on actual malicious activity. Works across SIEM platforms. Use when creating…

원문 언어: 영어

업데이트
직업 분류
소프트웨어 개발자
설명

Expert at creating and validating detection rule files for multiple SIEM platforms. Supports Splunk security_content YAML, Sigma rules, Elastic detection TOML, and KQL analytics. Ensures compliance with repository conventions and optimal query performance.…

원문 언어: 영어

업데이트
직업 분류
소프트웨어 개발자
설명

Analyze pull requests for detection coverage gaps and recommend additional detections, story alignments, and test coverage to extend PRs before merge.

원문 언어: 영어

업데이트
직업 분류
소프트웨어 개발자
설명

Optimize detection queries for performance across Splunk (SPL), Microsoft Sentinel (KQL), and Elastic Security (EQL/ES|QL). Covers search pipeline internals, common anti-patterns, and optimization techniques for detection rules on each platform.

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Analyze software supply chain attacks across package registries (npm, PyPI, RubyGems), CI/CD pipelines (GitHub Actions, GitLab CI), and container ecosystems. Includes detection engineering patterns for Splunk, Sentinel, Elastic, and Sigma.

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Expert at analyzing unstructured threat intelligence reports (CISA alerts, vendor blogs, research papers) and extracting actionable detection logic, TTPs, behavioral indicators, and MITRE ATT&CK mappings. Focuses on behaviors over IOCs. Use when provided with…

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Analyzes detection coverage using Sigma, Splunk, and Elastic rules. Use when checking coverage for techniques, tactics, threat actors, or generating Navigator layers from detections.

원문 언어: 영어

업데이트
수집된 skill 15개 중 15개를 표시합니다.