detection-engineering

Create and validate Sigma-based SIEM detection rules mapped to ATT&CK techniques.

Updated Apr 19, 2026
One-click install
npx skills add https://github.com/do360now/security-agents --skill detection-engineering-do360now
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: detection-engineering
Source: https://github.com/do360now/security-agents/tree/main/.claude/skills/detection-engineering
Command: npx skills add https://github.com/do360now/security-agents --skill detection-engineering-do360now

SYSTEM DOCUMENTATION & REQUIREMENTS

💡 This Skill includes scripts (resource) and references (resource) and assets (resource) components.

What problem does it solve?

This Skill streamlines the development of effective SIEM detection rules by providing structured guidance, technical analysis, and best practices aligned with the ATT&CK framework.

Core Features & Use Cases

  • Detection Strategy Design: Guides analysts through ATT&CK technique analysis, data source mapping, and false-positive reduction.
  • Rule Authoring: Provides templates and sample Sigma rules for various adversary techniques.
  • Operational Documentation: Produces comprehensive ADS documentation and heatmaps for coverage assessment and gap analysis.

Quick Start

Use the detection-engineering skill to develop a Sigma rule for suspicious PowerShell command-line activity and generate the corresponding ADS documentation.

Frequently Asked Questions about detection-engineering

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I create SIEM detection rules aligned with the ATT&CK framework?

SIEM detection rules aligned with the ATT&CK framework are created by analyzing adversary techniques, mapping data sources, and authoring Sigma rules. This systematic approach reduces false positives and ensures comprehensive threat coverage in security operations.

What is Sigma rule engineering for adversary behavior?

Sigma rule engineering for adversary behavior is the structured creation and validation of SIEM detections based on attack techniques. It involves technical analysis, rule design, and strategic documentation to enhance operational response and detection efficacy.

How do I map ATT&CK techniques to data sources for threat coverage?

Mapping ATT&CK techniques to data sources involves analyzing adversary behavior and identifying relevant logs. This process produces operational documentation like heatmaps for coverage assessment and gap analysis, ensuring detection efficacy in your security operations center.

Does this approach support generating ADS documentation and heatmaps?

Yes, this approach supports generating Attack Detection Strategy documentation and heatmaps. It provides comprehensive coverage assessment and gap analysis alongside rule authoring, testing, and deployment of Sigma rules aligned with attack behavior.

What is the best way to reduce false positives in Sigma rules?

The best way to reduce false positives in Sigma rules is through systematic detection strategy design. This involves structured ATT&CK technique analysis, precise data source mapping, and thorough rule testing before deploying to your SIEM.