Detection Sigma is an agent skill from AgentSecOps/SecOpsAgentKit. Generic detection rule creation and management using Sigma, the universal SIEM rule format. Sigma provides vendor-agnostic detection logic for log analysis across multiple SIEM platforms. Use when: (1) Creating detection rules for security monitoring, (2) Converting rules between SIEM platforms (Splunk, Elastic, QRadar, Sentinel), (3) Threat hunting with standardized detection patterns, (4) Building detection-as-code pipelines, (5) Mapping detections to MITRE ATT&CK tactics, (6) Implementing compliance-based…
Its SKILL.md is about 4k tokens, which your agent loads only when the skill is triggered. The skill folder holds 17 other files, including reference files and assets (for example `assets/compliance-rules/iso27001-logging.yml`, `assets/compliance-rules/nist-800-53-audit.yml` and `assets/compliance-rules/pci-dss-monitoring.yml`).
It sits in Security, covering Security operations. It works with Splunk. The repository describes itself as: Security operations toolkit for AI coding agents. Give Claude Code 25+ skills to catch vulnerabilities, scan containers, detect secrets, and enforce policies automatically.