← ClaudeAtlas

detection-rulelisted

Use when authoring a SIEM detection rule or use case — mapping to MITRE ATT&CK techniques, writing Sigma rules, and tuning false positives for Splunk/Elastic/Sentinel. Triggers on "detection rule", "SIEM use case", "Sigma rule", "ATT&CK detection", "alert tuning", "detection engineering".
noctua84/nescio-ai · ★ 0 · AI & Automation · score 73
Install: claude install-skill noctua84/nescio-ai
# Detection Rule ## Purpose Create a detection rule / SIEM use case that delivers actionable, measurable results. **Category**: Cybersecurity & Information Security ## Inputs ### Required - **Objective**: What you want to achieve with this deliverable - **Context**: Relevant background information (systems, scope, environment) ### Optional - **Constraints**: Any limitations or requirements to consider - **Existing Work**: Previous documents or data to build on ## Context Before starting, read the repo's `CLAUDE.md` and any relevant notes under `memory/` (e.g. `memory/repo/<repo>/`, `memory/feedback/`) for prior decisions and constraints. ## Process ### Step 1: Context & Research - Review any existing detection rule / siem use case documents in the project - Identify key stakeholders and their requirements - Select the most appropriate framework: Sigma Rules Standard, MITRE ATT&CK Detection, Splunk/Elastic/Sentinel Detection Frameworks ### Step 2: Analysis & Framework Application - Apply the selected framework to structure the detection rule / siem use case - Identify gaps, opportunities, and risks - Define success metrics: True Positive Rate, False Positive Rate, Alert Volume per Rule, ATT&CK Technique Coverage - Document assumptions and dependencies - Validate approach against industry best practices ### Step 3: Build the Deliverable - Structure the detection rule / siem use case using the output format below - Include specific, actionable recommendations — not g