detection-engineer

Convert malware analysis findings into Sigma and Suricata detection rules.

44|3|Updated Oct 27, 2025
One-click install
npx skills add https://github.com/gl0bal01/malware-analysis-claude-skills --skill detection-engineer
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: detection-engineer
Source: https://github.com/gl0bal01/malware-analysis-claude-skills/tree/main/detection-engineer
Command: npx skills add https://github.com/gl0bal01/malware-analysis-claude-skills --skill detection-engineer

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

Create detection rules and hunting queries from malware analysis findings to drive rapid, accurate detection across SIEMs, IDS/IPS, and threat hunting workflows.

Core Features & Use Cases

  • Sigma rule generation for SIEM detection across platforms (Splunk, Elastic, QRadar)
  • Suricata/NIDS rule creation for network visibility
  • Defanging IOCs for safe sharing and interoperability
  • Hunting queries and reporting to operationalize findings for SOC teams
  • Format conversion of IOCs and detections (STIX, OpenIOC, CSV) with confidence and volatility assessment

Quick Start

Use this skill to convert a malware analysis finding into Sigma and Suricata rules, generate hunting queries, and export IOCs in standard formats for SOC deployment.

Frequently Asked Questions about detection-engineer

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I generate Sigma rules from malware analysis findings?

To generate Sigma rules from malware analysis findings, provide the analysis results to the Skill, which authors, validates, and documents production-ready detection rules for SIEM platforms like Splunk, Elastic, and QRadar.

Can I create Suricata rules for network visibility from malware analysis?

Yes, you can create Suricata rules for network visibility by feeding malware analysis findings into the Skill, which translates indicators and behaviors into NIDS rules for network detection.

What is the best way to defang IOCs for safe sharing across SOC teams?

The best way to defang IOCs for safe sharing is to use the Skill's defanging feature, which processes harvested indicators into interoperable formats like STIX, OpenIOC, and CSV for secure SOC distribution.

Does this detection engineering workflow support Splunk, Elastic, and QRadar?

Yes, this detection engineering workflow supports Splunk, Elastic, and QRadar by generating Sigma rules compatible across these SIEM platforms, ensuring broad deployment for threat hunting and SOC teams.

How do I convert IOCs between STIX, OpenIOC, and CSV formats?

To convert IOCs between STIX, OpenIOC, and CSV formats, input harvested indicators into the Skill, which performs format conversion while assessing indicator confidence and volatility for operational threat hunting.

When do I need to operationalize malware findings into hunting queries?

You need to operationalize malware findings into hunting queries when transitioning from static analysis to active threat hunting, enabling SOC teams to proactively search for validated indicators and behaviors across enterprise networks.