detection-test-engineer

Generate and execute security detection test scenarios across SIEM platforms.

471|74|Updated Jan 13, 2026
One-click install
npx skills add https://github.com/MHaggis/Security-Detections-MCP --skill detection-test-engineer
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: detection-test-engineer
Source: https://github.com/MHaggis/Security-Detections-MCP/tree/main/.claude/skills/detection-test-engineer
Command: npx skills add https://github.com/MHaggis/Security-Detections-MCP --skill detection-test-engineer

SYSTEM DOCUMENTATION & REQUIREMENTS

💡 This Skill includes references (resource) components.

What problem does it solve?

This Skill automates the creation and execution of test scenarios to validate the effectiveness of security detections, ensuring they accurately trigger on malicious activity.

Core Features & Use Cases

  • Test Scenario Generation: Creates comprehensive tests using Atomic Red Team, custom scripts, or direct simulation.
  • SIEM Platform Agnostic: Works across Splunk, Sentinel, Elastic, and Sigma platforms.
  • Use Case: You've just written a new detection rule for a MITRE ATT&CK technique. Use this Skill to generate a test case, execute it in your lab environment, and confirm the detection fires correctly.

Quick Start

Use the detection-test-engineer skill to create a test scenario for the T1003.001 technique.

Frequently Asked Questions about detection-test-engineer

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I validate security detections across multiple SIEM platforms?

Validate security detections by generating and executing test scenarios across Splunk, Sentinel, Elastic, and Sigma platforms to confirm they accurately trigger on malicious activity.

What is the best way to test a SIEM detection rule for a specific MITRE ATT&CK technique?

The best way to test a SIEM detection rule for a MITRE ATT&CK technique is to generate a test case using Atomic Red Team or custom scripts, execute it in a lab environment, and confirm the detection fires correctly.

Can I use Atomic Red Team to create test scenarios for Splunk or Elastic security detections?

Yes, you can use Atomic Red Team to generate comprehensive test scenarios for validating Splunk, Sentinel, Elastic, and Sigma security detections.

Do I need a dedicated test environment like Attack Range to validate detection logic?

Yes, validating detection logic requires integration with test environments like Attack Range to safely execute simulations and adhere to pragmatic testing philosophies for accurate results.

How do I generate a test case for the T1003.001 MITRE technique?

You generate a test case for the T1003.001 technique by applying the detection-test-engineer skill to create a specific test scenario, executing it in your lab, and verifying the rule triggers correctly.

Why are my SIEM security detections not triggering during threat hunting simulations?

Security detections may not trigger during threat hunting simulations if they lack proper validation through generated test scenarios using Atomic Red Team or direct simulation in an integrated lab environment.