pentest-detection-engineer

Generate detection rules in Sigma, Splunk SPL, KQL, YARA, and Snort formats.

Updated Jun 21, 2026
One-click install
npx skills add https://github.com/infantesromeroadrian/arca-agent --skill pentest-detection-engineer
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: pentest-detection-engineer
Source: https://github.com/infantesromeroadrian/arca-agent/tree/main/template/skills/pentest-detection-engineer
Command: npx skills add https://github.com/infantesromeroadrian/arca-agent --skill pentest-detection-engineer

SYSTEM DOCUMENTATION & REQUIREMENTS

💡 This Skill includes scripts (resource) and references (resource) components.

What problem does it solve?

This Skill provides expert detection engineering support for security operations, including building detection rules, threat hunting queries, and security monitoring content.

Core Features & Use Cases

  • Detection Rule Creation: Generates detection rules in various formats like Sigma, Splunk SPL, Elastic KQL/EQL, Microsoft Sentinel KQL, YARA, and Snort/Suricata.
  • Log Source Expertise: Works with a wide range of log sources including Windows, Linux, Network, Endpoint, Cloud, and Identity logs.
  • Threat Hunting: Offers threat hunting content with hypotheses, data sources, hunt queries, pivot points, and success criteria.
  • Behavioral Rules: Produces deployable rules with actionable false positive guidance, layer detection, and evasion considerations.

Quick Start

Use the pentest-detection-engineer skill to create a detection rule for a specific attack technique in the 'redteam' directory.

Frequently Asked Questions about pentest-detection-engineer

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I create detection rules for security monitoring across multiple platforms?

Detection rule creation generates security monitoring content in formats like Sigma, Splunk SPL, Elastic KQL, and Microsoft Sentinel KQL. It supports various log sources including Windows, Linux, Network, Endpoint, Cloud, and Identity logs for comprehensive coverage.

What log sources are supported for threat hunting queries?

Threat hunting queries operate on Windows, Linux, Network, Endpoint, Cloud, and Identity log sources. The skill provides hypotheses, data sources, hunt queries, pivot points, and success criteria for comprehensive threat hunting across these environments.

Can I generate YARA and Snort rules for endpoint and network detection?

Yes, detection rule creation supports YARA and Snort/Suricata formats alongside Sigma, Splunk SPL, Elastic KQL/EQL, and Microsoft Sentinel KQL. These cover endpoint and network detection across various log sources.

What's the best way to reduce false positives in behavioral detection rules?

Behavioral rules include actionable false positive guidance, layer detection, and evasion considerations. This approach ensures deployable rules with minimized false positives across Windows, Linux, Network, Endpoint, Cloud, and Identity log sources.

Do I need security operations expertise to use this detection engineering skill?

Yes, the skill requires expertise in security operations and threat hunting. It provides expert detection engineering support but expects foundational knowledge of log analysis, security monitoring, and threat hunting methodologies.

How do I start building detection rules for a specific attack technique?

Use the skill to create detection rules for specific attack techniques by providing log source details and desired output format. It generates rules in Sigma, Splunk SPL, Elastic KQL/EQL, Microsoft Sentinel KQL, YARA, or Snort/Suricata formats.

Related Skills