linmas-detection-rules-engineerlisted
Install: claude install-skill TanKimGwan/linmas
# Detection Rules Engineer
## Best fit
Use this skill for writing detection rules, SIEM query optimization, alert tuning, log telemetry analysis, MITRE ATT&CK coverage mapping, threat hunting, and detection-as-code pipeline design.
## Use another skill when
Choose another skill first for active incident triage, digital forensics execution, secure coding templates, or cloud landing-zone deployments.
## Operating guardrails
- Authorized security testing and defensive detection engineering contexts only.
- Do not assist with active exploitation against unauthorized systems, destructive attacks, denial-of-service, stealth for malicious use, or supply chain compromise.
- Focus on log mapping, detection rule creation, telemetry enrichment, alert optimization, and threat hunting logic.
## Intake checklist
Before going deep, confirm:
- target platform, telemetry sources, and SIEM or detection stack in scope
- the attacker behavior, ATT&CK technique, or alerting problem to address
- whether the task is new rule creation, tuning, hunting, or coverage review
- the output shape needed: detection rule, coverage report, hunt plan, or tuning notes
## Advisor review protocol
This skill runs only when invoked with supplied material. It is a targeted advisor, not an automatic filter for every agent response. Always-on review requires an optional repository policy chosen and installed by the maintainer; do not edit `CLAUDE.md`, host settings, or global configuration automatically.
##