opentide avatar

opentide

Official

@opentidehq

0Followers
|
8Public Repos
|
27Published Skills

Open Threat Informed Detection Engineering is a comprehensive framework to enable Threat & Detection Modelling and Detection-as-Code in a unified workflow

Skills Distribution
DomainCybersecurit...Threat Detection E.. (40%)Telemetry & Log An.. (30%)Security Operation.. (30%)

Agent Skills by opentide

Showing 27 vetted skills indexed across 1 GitHub repositories.

OpenTideHQOpenTideHQ
4

windows-internals

Explain Windows OS internals and map telemetry signals to validate detection hypotheses.

Official
Basic
OpenTideHQOpenTideHQ
4

okta-identity

Detect Okta System Log events for identity and access anomalies.

Official
Advanced
OpenTideHQOpenTideHQ
4

detection-engineering

Coordinate detection content lifecycle from hunting validation to production MDR rules.

Official
Advanced
OpenTideHQOpenTideHQ
4

harfanglab

Convert HarfangLab EDR content into CoreTide YAML with validated selectors and fields.

Official
Advanced
OpenTideHQOpenTideHQ
4

entra-id

Map Microsoft Entra ID telemetry logs to detection patterns.

Official
Advanced
OpenTideHQOpenTideHQ
4

opentide-detection-rule

Create deployable MDR detection rules with platform-specific metadata and cross-platform configurations.

Official
Advanced
OpenTideHQOpenTideHQ
4

microsoft-defender-endpoint

Craft Defender for Endpoint Advanced Hunting queries with correct table schemas and constraints.

Official
Advanced
OpenTideHQOpenTideHQ
4

carbon-black-cloud

Plan and document Carbon Black Cloud Enterprise EDR detection content across surfaces.

Official
Advanced
OpenTideHQOpenTideHQ
4

windows-event-logs

Document Windows-native telemetry sources and audit policy prerequisites for detection engineering.

Official
Advanced
OpenTideHQOpenTideHQ
4

crowdstrike-falcon

Author CrowdStrike Falcon detections across Event Search, NG-SIEM, IOAs, Fusion, and RTR.

Official
Advanced
OpenTideHQOpenTideHQ
4

network-protocols

Explain network protocol internals for detection engineering across DNS, TLS, SMB, and more.

Official
Advanced
OpenTideHQOpenTideHQ
4

threat-hunting

Generate ABLE-based hunting hypotheses from intelligence data into OpenTide TVM/DOM/MDR constructs.

Official
Advanced
OpenTideHQOpenTideHQ
4

microsoft-sentinel

Codify Microsoft Sentinel hunting and analytic-rule creation best practices.

Official
Advanced
OpenTideHQOpenTideHQ
4

microsoft-azure

Organize Azure Activity Log, RBAC, PIM, Key Vault, Storage, Compute, Network, and Defender signals for detection engineering.

Official
Advanced
OpenTideHQOpenTideHQ
4

opentide-detection-objective

Defines structured detection objectives for mapping between threats and MDR rules.

Official
Advanced
OpenTideHQOpenTideHQ
4

splunk

Create Splunk SPL detection engineering searches with CIM data models and tstats.

Official
Advanced
OpenTideHQOpenTideHQ
4

linux-internals

Translate Linux internals into actionable detection engineering knowledge.

Official
Advanced
OpenTideHQOpenTideHQ
4

google-cloud-platform

Interpret GCP Cloud Audit Logs and IAM mechanics for abuse detection.

Official
Advanced
OpenTideHQOpenTideHQ
4

opentide-threat-vector

Convert CTI reports into TVM YAML with ATT&CK mappings and UUIDs.

Official
Advanced
OpenTideHQOpenTideHQ
4

active-directory

Map Active Directory authentication, replication, and trust mechanisms to detection requirements.

Official
Advanced
OpenTideHQOpenTideHQ
4

kusto-query-language

Provide platform-agnostic KQL patterns and optimisation rules for cross-platform queries.

Official
Advanced
OpenTideHQOpenTideHQ
4

sentinelone-singularity

Author SentinelOne Singularity detection content across STAR, DVQL, and SDL analytics.

Official
Advanced
OpenTideHQOpenTideHQ
4

email-and-collaboration

Encode Microsoft 365 email and collaboration telemetry for threat detection.

Official
Advanced
OpenTideHQOpenTideHQ
4

identity-providers

Detect authentication protocol abuse across OAuth2/OIDC and SAML IdPs.

Official
Advanced

Frequently Asked Questions About opentide

FAQPage Schema
What specific security tasks does OpenTide enable?

OpenTide enables the structured mapping of threat intelligence to detection rules, the codification of hunting hypotheses, and the normalization of telemetry from diverse sources like Microsoft Sentinel, Splunk, and various EDR platforms into consistent detection objectives.

Which technical personas benefit from these detection engineering frameworks?

Security engineers, threat hunters, and detection developers benefit from these frameworks by gaining a standardized methodology for authoring, validating, and deploying detection content across complex hybrid-cloud and endpoint environments.

What are the primary prerequisites for implementing these detection patterns?

Implementation requires foundational knowledge of OS internals, specifically Windows, Linux, and macOS, alongside familiarity with cloud telemetry sources like AWS CloudTrail, GCP Audit Logs, and Microsoft Entra ID identity signals.