harfanglab

Convert HarfangLab EDR content into CoreTide YAML with validated selectors and fields.

4|1|Updated Apr 28, 2026
One-click install
npx skills add https://github.com/OpenTideHQ/AgentTide --skill harfanglab
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: harfanglab
Source: https://github.com/OpenTideHQ/AgentTide/tree/main/skills/harfanglab
Command: npx skills add https://github.com/OpenTideHQ/AgentTide --skill harfanglab

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

This skill encodes HarfangLab EDR content authoring concepts into CoreTide's validated YAML schema, enabling consistent, machine-readable rule authoring for detection engineering.

Core Features & Use Cases

  • Sigma-based detection rule authoring in CoreTide format with selections, modifiers, and validated fields.
  • RHQL hunting support with structured queries and auto-routing for efficient in-context evaluation.
  • YARA rule authoring with CoreTide's schema, including meta, imports, and cross-product context for MDR ingestion.

Quick Start

Describe how to generate CoreTide YAML for HarfangLab content authoring and validate the Sigma, RHQL, and YARA surfaces.

Frequently Asked Questions about harfanglab

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I author Sigma detection rules for HarfangLab EDR?

Author Sigma detection rules for HarfangLab EDR by converting them into validated CoreTide YAML. This applies structured selections, modifiers, and fields to ensure machine-readable detection content and accurate activation.

Can I use YARA rules with HarfangLab for MDR ingestion?

Yes, you can use YARA rules with HarfangLab for MDR ingestion. The skill formats YARA rules into CoreTide's schema, including necessary imports, meta definitions, and cross-product context for accurate detection.

Does HarfangLab content authoring support RHQL hunting queries?

HarfangLab content authoring supports RHQL hunting by generating structured queries with auto-routing. This enables efficient in-context evaluation of threats across Windows, macOS, and Linux environments.

What is the harfanglab::1.0 schema for detection content?

The harfanglab::1.0 schema is a validated YAML structure for detection content. It ensures compliance by enforcing proper imports, meta, and context definitions across Sigma rules and YARA integrations.

How do I validate selectors and fields for CoreTide YAML?

Validate selectors and fields for CoreTide YAML by applying the harfanglab::1.0 schema. This ensures all detection rules maintain correct modifiers, imports, and context definitions for production-grade routing.