What problem does it solve?
This Skill reduces noisy, fragile, or incorrect SIEM detections by providing structured, framework-mapped guidance to build and tune KQL/SPL detection rules that are suitable for production use.
Core Features & Use Cases
- SIEM detection rule authoring: Produce KQL (Microsoft Sentinel) or SPL (Splunk) queries for common detection patterns such as thresholding, time windows, aggregation, and correlation.
- ATT&CK mapping for auditability: Align rule logic to MITRE ATT&CK v16 techniques to support consistent coverage across a SOC workflow.
- Threshold tuning and lifecycle management: Recommend baselining, suppression, scheduling, and ongoing maintenance steps so detections improve over time instead of staying static.
Quick Start
Ask the agent to write and tune a Sentinel (KQL) or Splunk (SPL) SIEM detection rule for a specific MITRE ATT&CK technique ID, using your available log table/index and expected false-positive constraints.