MHaggisMHaggisCommunityยท15 Agent Skills Included

Security-Detections-MCP

Security detection search, coverage analysis, and adversary testing

Searches and analyzes 8,200+ security detection rules across Sigma, Splunk, Elastic, KQL, Sublime, and CrowdStrike formats. Maps detections to MITRE ATT&CK techniques, finds coverage gaps, and generates Navigator heatmap layers. Guides Atomic Red Team testing, detection rule authoring, query optimization, and threat report parsing without manual SIEM work.
npx skills add MHaggis/Security-Detections-MCP --all -g -y

All Skills in This Repository (15)

Pure Emerald Level Indicators
๐Ÿ“ฆ In Repo
MHaggisMHaggis

Custom Atomics Deployment

Create, deploy, and execute custom Atomic Red Team YAML tests.

Community
Advanced
๐Ÿ“ฆ In Repo
MHaggisMHaggis

Atomic Red Team Testing

Execute and validate Atomic Red Team adversary emulation tests across SIEMs.

Community
Advanced
๐Ÿ“ฆ In Repo
MHaggisMHaggis

detection-test-engineer

Generate and execute security detection test scenarios across SIEM platforms.

Community
Advanced
๐Ÿ“ฆ In Repo
MHaggisMHaggis

Supply Chain Attack Analyst

Analyze software supply chain attacks and generate SIEM detection rules.

Community
Advanced
๐Ÿ“ฆ In Repo
MHaggisMHaggis

detection-coverage-analysis

Analyze security detection coverage against MITRE ATT&CK using Sigma, Splunk, and Elastic rules.

Community
Intermediate
๐Ÿ“ฆ In Repo
MHaggisMHaggis

Data Source Mapper

Map MITRE ATT&CK techniques to data sources across SIEM schemas.

Community
Intermediate
๐Ÿ“ฆ In Repo
MHaggisMHaggis

PR Extension Workflow

Analyze pull requests for security detection coverage gaps and recommend extensions.

Community
Advanced
๐Ÿ“ฆ In Repo
MHaggisMHaggis

detection-yaml-engineer

Generate and validate security detection rules for Splunk, Sigma, Elastic, and KQL.

Community
Intermediate
๐Ÿ“ฆ In Repo
MHaggisMHaggis

detection-reviewer

Validate security detection rules in SPL, KQL, Sigma, and Elastic formats.

Community
Advanced
๐Ÿ“ฆ In Repo
MHaggisMHaggis

Test Environment Builder

Build adversary emulation lab environments across Splunk, Elastic Security, and Microsoft Sentinel.

Community
Advanced
๐Ÿ“ฆ In Repo
MHaggisMHaggis

cti-detection-engineer

Generate multi-SIEM detection logic from threat intelligence and MITRE ATT&CK mappings.

Community
Advanced
๐Ÿ“ฆ In Repo
MHaggisMHaggis

ATT&CK Navigator Layer Generator

Generate MITRE ATT&CK Navigator JSON layers for detection coverage and gap analysis.

Community
Intermediate

Frequently Asked Questions

FAQPage Schema
How to install Security-Detections-MCP?โ–ผ

Run `npx skills add MHaggis/Security-Detections-MCP --all -g -y` in your terminal to install all skills in this suite globally.

What does Security-Detections-MCP do?โ–ผ

It gives you a unified, searchable database of over 8,200 detection rules from Sigma, Splunk ESCU, Elastic, KQL, Sublime, and CrowdStrike, plus MITRE ATT&CK threat actor mappings and coverage analysis.

How to find detection coverage gaps?โ–ผ

Use the coverage analysis skills to score your detections by tactic and technique, identify gaps against threat profiles like ransomware or APT groups, and export ATT&CK Navigator layers for visualization.

Can it help write and test new detection rules?โ–ผ

Yes. It includes skills for authoring rules in Splunk YAML, Sigma, KQL, and Elastic TOML formats, plus Atomic Red Team testing workflows to validate that detections actually fire on real attack telemetry.

Does it work with Claude Code and Cursor?โ–ผ

Yes. All skills follow the standard SKILL.md format and run in Claude Code, Cursor, and other compatible coding environments.

Related Repositories in Software Engineering

View All in Software Engineeringโ†’