opentide
Official@opentidehq
Open Threat Informed Detection Engineering is a comprehensive framework to enable Threat & Detection Modelling and Detection-as-Code in a unified workflow
Agent Skills by opentide
Showing 27 vetted skills indexed across 1 GitHub repositories.
windows-internals
Explain Windows OS internals and map telemetry signals to validate detection hypotheses.
okta-identity
Detect Okta System Log events for identity and access anomalies.
detection-engineering
Coordinate detection content lifecycle from hunting validation to production MDR rules.
harfanglab
Convert HarfangLab EDR content into CoreTide YAML with validated selectors and fields.
entra-id
Map Microsoft Entra ID telemetry logs to detection patterns.
opentide-detection-rule
Create deployable MDR detection rules with platform-specific metadata and cross-platform configurations.
microsoft-defender-endpoint
Craft Defender for Endpoint Advanced Hunting queries with correct table schemas and constraints.
carbon-black-cloud
Plan and document Carbon Black Cloud Enterprise EDR detection content across surfaces.
windows-event-logs
Document Windows-native telemetry sources and audit policy prerequisites for detection engineering.
crowdstrike-falcon
Author CrowdStrike Falcon detections across Event Search, NG-SIEM, IOAs, Fusion, and RTR.
network-protocols
Explain network protocol internals for detection engineering across DNS, TLS, SMB, and more.
threat-hunting
Generate ABLE-based hunting hypotheses from intelligence data into OpenTide TVM/DOM/MDR constructs.
microsoft-sentinel
Codify Microsoft Sentinel hunting and analytic-rule creation best practices.
microsoft-azure
Organize Azure Activity Log, RBAC, PIM, Key Vault, Storage, Compute, Network, and Defender signals for detection engineering.
opentide-detection-objective
Defines structured detection objectives for mapping between threats and MDR rules.
splunk
Create Splunk SPL detection engineering searches with CIM data models and tstats.
linux-internals
Translate Linux internals into actionable detection engineering knowledge.
google-cloud-platform
Interpret GCP Cloud Audit Logs and IAM mechanics for abuse detection.
opentide-threat-vector
Convert CTI reports into TVM YAML with ATT&CK mappings and UUIDs.
active-directory
Map Active Directory authentication, replication, and trust mechanisms to detection requirements.
kusto-query-language
Provide platform-agnostic KQL patterns and optimisation rules for cross-platform queries.
sentinelone-singularity
Author SentinelOne Singularity detection content across STAR, DVQL, and SDL analytics.
email-and-collaboration
Encode Microsoft 365 email and collaboration telemetry for threat detection.
identity-providers
Detect authentication protocol abuse across OAuth2/OIDC and SAML IdPs.
Frequently Asked Questions About opentide
FAQPage SchemaWhat specific security tasks does OpenTide enable?▼
OpenTide enables the structured mapping of threat intelligence to detection rules, the codification of hunting hypotheses, and the normalization of telemetry from diverse sources like Microsoft Sentinel, Splunk, and various EDR platforms into consistent detection objectives.
Which technical personas benefit from these detection engineering frameworks?▼
Security engineers, threat hunters, and detection developers benefit from these frameworks by gaining a standardized methodology for authoring, validating, and deploying detection content across complex hybrid-cloud and endpoint environments.
What are the primary prerequisites for implementing these detection patterns?▼
Implementation requires foundational knowledge of OS internals, specifically Windows, Linux, and macOS, alongside familiarity with cloud telemetry sources like AWS CloudTrail, GCP Audit Logs, and Microsoft Entra ID identity signals.