threat-detection-engineer

Author Sigma detection rules with MITRE ATT&CK mapping for SIEM deployment.

1|Updated Mar 13, 2026
One-click install
npx skills add https://github.com/coreymaypray/sloth-skill-tree --skill threat-detection-engineer-coreymaypray
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: threat-detection-engineer
Source: https://github.com/coreymaypray/sloth-skill-tree/tree/main/plugins/maycrest-secure/skills/threat-detection-engineer
Command: npx skills add https://github.com/coreymaypray/sloth-skill-tree --skill threat-detection-engineer-coreymaypray

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

Writes precise, low-noise detections to reduce alert fatigue and improve threat visibility across enterprise SIEMs and application telemetry.

Core Features & Use Cases

  • Sigma rule authoring with MITRE ATT&CK mapping
  • Threat hunting hypotheses and structured hunts
  • Detection-as-code pipelines with CI/CD deployment to SIEMs

Quick Start

Generate a Sigma rule to detect credential stuffing in Supabase Auth logs and validate it against sample data.

Frequently Asked Questions about threat-detection-engineer

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I write Sigma rules mapped to MITRE ATT&CK techniques?

Author Sigma rules by writing detection logic mapped directly to specific MITRE ATT&CK techniques, ensuring high-fidelity SIEM detections with confidence and validated threat coverage.

What is the best way to reduce SIEM alert fatigue with high-fidelity detections?

Reduce SIEM alert fatigue by developing precise, low-noise detections and validated playbooks that improve threat visibility across enterprise SIEMs and application telemetry.

How do I build a detection-as-code pipeline with CI/CD deployment?

Build detection-as-code pipelines by integrating Sigma rule authoring with CI/CD processes, enabling automated, testable, and deployable detections directly into enterprise SIEMs.

Can I generate Sigma rules to detect credential stuffing in Supabase Auth logs?

Generate Sigma rules to detect credential stuffing in Supabase Auth logs and validate them against sample data to ensure application-layer anomaly detection works.

How do I create threat hunting hypotheses for structured hunts?

Create threat hunting hypotheses by developing structured hunts driven by validated playbooks, ensuring testable and deployable detections aligned with enterprise SIEM rule development.

Does this approach work for application-layer anomaly detection in Supabase-backed apps?

Detection engineering works for application-layer anomaly detection in Supabase-backed apps by authoring Sigma rules and validating them against sample data for precise detections.