detection-engineering

Coordinate detection content lifecycle from hunting validation to production MDR rules.

4|1|Updated Apr 28, 2026
One-click install
npx skills add https://github.com/OpenTideHQ/AgentTide --skill detection-engineering-opentidehq
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: detection-engineering
Source: https://github.com/OpenTideHQ/AgentTide/tree/main/skills/detection-engineering
Command: npx skills add https://github.com/OpenTideHQ/AgentTide --skill detection-engineering-opentidehq

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

Detection engineering bridges the gap between hunting validation and production detection rules, ensuring scalable and reliable MDR deployments.

Core Features & Use Cases

  • End-to-end lifecycle management from TVM to DOM to MDR, enabling consistent content lineage.
  • Hunt-to-rule conversion with FP reduction, entity mapping, and NRT compliance across platforms.
  • Multi-platform readiness with maturation guidance for PR scope and quality bars.

Quick Start

Describe how to convert validated hunts into production MDR detections using the 7-step workflow across TVM, DOM, and MDR.

Frequently Asked Questions about detection-engineering

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
What is detection engineering for converting threat hunts into MDR rules?

Detection engineering is the process of bridging hunting validation and production detection rules to ensure scalable and reliable MDR deployments. It manages the end-to-end content lifecycle across TVM, DOM, and MDR components.

How do I convert validated hunts into production MDR detections?

You convert validated hunts into production MDR detections by applying a 7-step hunt-to-detection workflow across OpenTide components. This enforces platform-specific configurations, entity mapping, and FP reduction for reliable rules.

Does the hunt-to-detection workflow enforce PR discipline and quality gates?

Yes, the hunt-to-detection workflow enforces PR discipline and quality gates. It provides multi-platform readiness with maturation guidance for PR scope, ensuring content lineage from TVM to DOM to MDR meets quality bars.

Can I manage multi-phase MDR deployments across different OpenTide platform pairings?

Yes, you can plan multi-phase MDR deployments across OpenTide platform pairings. The workflow ensures multi-platform readiness with NRT compliance, maturation guidance, and consistent content lineage across TVM, DOM, and MDR.

What's the best way to reduce false positives when deploying MDR detection rules?

The best way to reduce false positives in MDR detection rules is using the hunt-to-rule conversion workflow. It applies entity mapping, NRT compliance, and quality gates across platform pairings to ensure scalable, production-ready detections.

When do I need entity mapping and NRT compliance for MDR detection content?

You need entity mapping and NRT compliance when converting validated hunts into production MDR rules. These steps ensure platform-specific configurations meet quality bars and support reliable, multi-phase deployments across OpenTide components.