Agent skill

Siem Detection

by briiirussell in briiirussell/cybersecurity-skills

Engineer and audit SIEM detection rules — log source coverage, Sigma / KQL / SPL / Elastic query authoring, MITRE ATT&CK mapping, false-positive tuning, and detection-as-code workflows.

MITAuto-check: notesSecurity

Install Siem Detection

skills CLI
$ npx skills add briiirussell/cybersecurity-skills --skill siem-detection -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install briiirussell/cybersecurity-skills siem-detection --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/briiirussell/cybersecurity-skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/siem-detection .claude/skills/siem-detection && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
siem-detection
GitHub stars
413
Token cost
~2.6k tokens
SKILL.md length
1,033 words
Files
1
Skills in repo
25
Repo updated
First seen
Licence
MIT

At a glance

Engineer and audit SIEM detection rules — log source coverage, Sigma / KQL / SPL / Elastic query authoring, MITRE ATT&CK mapping, false-positive tuning, and detection-as-code workflows.

  • Works in 6 steps: Map log sources to ATT&CK coverage → Pick the right detection model per case → Write the rule → …
  • The user mentions SIEM
  • SKILL.md covers Scope, Methodology, Output Format and Boundaries, plus 1 more section
  • Reaches attack.mitre.org

What it does

Siem Detection is an agent skill from briiirussell/cybersecurity-skills. Engineer and audit SIEM detection rules — log source coverage, Sigma / KQL / SPL / Elastic query authoring, MITRE ATT&CK mapping, false-positive tuning, and detection-as-code workflows. Use when the user mentions 'SIEM,' 'detection engineering,' 'detection rules,' 'Sigma,' 'KQL,' 'SPL,' 'Splunk,' 'Sentinel,' 'Elastic,' 'Wazuh,' 'Chronicle,' 'detection-as-code,' 'MITRE ATT&CK mapping,' 'log coverage,' 'alert tuning,' 'use case development,' or needs help building or improving security detections.

Its SKILL.md is about 2.6k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Security, covering Security operations. It works with Microsoft Sentinel and Splunk. The repository describes itself as: Cybersecurity skills for AI coding agents (Claude Code, Cursor, Codex). The licence is MIT.

When your agent uses it

  • The user mentions SIEM
  • Detection engineering
  • Detection rules
  • Detection-as-code

Example prompts

  • “detection engineering,”
  • “detection rules,”
  • “Sigma,”
  • “/siem-detection”

Requirements

  • Python 3
  • Pre-approved tools (allowed-tools): Read, Write, Bash, Grep, Glob, WebSearch

Workflow steps

6 steps, taken from the step headings in SKILL.md.

  1. Map log sources to ATT&CK coverage
  2. Pick the right detection model per case
  3. Write the rule
  4. Map to MITRE ATT&CK
  5. Tune
  6. Detection-as-code

What it can do on your machine

Read from SKILL.md and the folder at commit c9ade03. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves these tools, so the agent can use them without asking each time:

    • Read
    • Write
    • Bash
    • Grep
    • Glob
    • WebSearch

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md (its code samples are yaml, kql, spl, esql and markdown).

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Hosts in commands or code, which the agent is likely to contact:

    • attack.mitre.org

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Siem Detection loads about 2.6k tokens when it runs. Until then it costs about 129 tokens; SKILL.md has 1,033 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~129
When it runs · the whole SKILL.md, loaded when a task matches
~2.6k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check: notes

The automated check noted patterns worth knowing about, such as sudo or a known installer.

  • NotePre-approves every shell command (allowed-tools: Bash)SKILL.md
    allowed-tools: Read, Write, Bash, Grep, Glob, WebSearch

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from briiirussell/cybersecurity-skills at commit c9ade03, republished under its MIT licence (© briiirussell). 1,033 words, ~2,609 tokens.

Download SKILL.mdSave it as .claude/skills/siem-detection/SKILL.md (or your agent's skills folder).
name
siem-detection
description
Engineer and audit SIEM detection rules — log source coverage, Sigma / KQL / SPL / Elastic query authoring, MITRE ATT&CK mapping, false-positive tuning, and detection-as-code workflows. Use when the user mentions 'SIEM,' 'detection engineering,' 'detection rules,' 'Sigma,' 'KQL,' 'SPL,' 'Splunk,' 'Sentinel,' 'Elastic,' 'Wazuh,' 'Chronicle,' 'detection-as-code,' 'MITRE ATT&CK mapping,' 'log coverage,' 'alert tuning,' 'use case development,' or needs help building or improving security detections.
allowed-tools
Read, Write, Bash, Grep, Glob, WebSearch

SIEM Detection — Detection Engineering

Build, audit, and maintain SIEM detection content — the rules that fire alerts. Distinct from incident-triage (responds when alerts fire) and from soc-operations (runs the SOC that triages alerts). This skill is the engineering layer: log coverage, rule authoring, tuning, and detection-as-code workflows.

Cross-references: incident-triage for what happens after the alert, threat-hunting for proactive hypothesis-driven hunts that often graduate into detection rules, breach-patterns for detection ideas pulled from public breach disclosures, soc-operations for the alert-triage operations on top of the detections engineered here.

Scope

This skill covers:

  • Log source coverage assessment ("are we even collecting the events we'd need to detect X?")
  • Rule authoring across major SIEM query languages (Sigma, KQL, SPL, Elastic ES|QL, Chronicle YARA-L)
  • MITRE ATT&CK mapping — every rule tagged with technique IDs for coverage analysis
  • Detection-as-code workflows (rules in Git, CI tests, deployment automation)
  • Alert tuning workflow — reducing false positives without losing true positives
  • Coverage gap analysis using ATT&CK Navigator

This skill does NOT cover:

  • Live alert triage (that's incident-triage)
  • Building a SOC team or alert escalation criteria (soc-operations)
  • Active threat hunting (threat-hunting)

Methodology

Step 1: Map log sources to ATT&CK coverage

Before writing any rule, audit what you can detect.

Categorize log sources by what they observe:

CategorySourcesObserves
EndpointEDR (CrowdStrike, SentinelOne, Defender), Sysmon, osqueryProcess exec, file write, network, registry, parent-child
NetworkZeek/Bro, Suricata, NSM, firewall, DNS query logsConnections, protocols, DNS queries, TLS metadata
IdentityOkta, Entra ID, AD, Auth0, GCP/AWS sign-inAuthentications, MFA, group changes, role assignments
CloudCloudTrail (AWS), Audit Logs (GCP), Activity Log (Azure)API calls — what was created/changed/deleted
ApplicationApp logs, WAF logs, load balancer logs, gateway logsRequest URLs, status codes, auth outcomes
SaaSGoogle Workspace, M365, Salesforce, GitHub auditAdmin actions, sharing, sensitive doc access

Run a gap check:

  • Pull the MITRE ATT&CK Enterprise matrix
  • For each technique relevant to your environment, ask: which of my log sources would surface this?
  • Techniques with NO source mapped are blind spots — write them down before writing any rules

Common blind spots:

  • Endpoint logs but no command-line argument capture (most Windows event logs default to logging only the binary, not the args)
  • Cloud audit logs collected but ReadOnly: true events filtered out — pre-attack recon invisible
  • No SaaS audit logs — every modern attack involves a SaaS pivot at some point
  • App logs without correlation IDs — can't connect "WAF saw payload" to "app processed payload"
Step 2: Pick the right detection model per case

Not every threat needs a SIEM rule. Match the detection model to what you're detecting.

Threat characterBest modelExample
Known IOC (hash, IP, domain)Threat-intel lookupSysmon hash matches known malware
Known pattern (specific command, specific path)Signature rulepowershell.exe -enc <base64>
Known anomaly (behavior outside baseline)Statistical detectionService account suddenly authenticating from new geography
Sequence of eventsCorrelation ruleFailed logon → success → privilege change in 5 min
Novel / never-seen-beforeThreat hunting (see threat-hunting)Hypothesis-driven SIEM search
Insider abuseUEBA / risk scoringCumulative risky behaviors weighted over time

Signature rules are cheapest to write and easiest to tune; statistical detections need baseline data and produce more false positives in the first month.

Step 3: Write the rule
Use Sigma as the source of truth where possible

Sigma is the cross-SIEM detection format. Write the rule in Sigma; auto-convert to your backend via sigmac / sigma-cli / pySigma. Even if you only target Splunk today, future-you will thank you.

yaml
title: AWS IAM CreateUser Followed by AttachUserPolicy
id: <UUID>
status: experimental
description: Detects an identity creating a new IAM user and immediately attaching an admin policy
references:
  - https://attack.mitre.org/techniques/T1136/003/
author: <name>
date: 2026-05-26
tags:
  - attack.persistence
  - attack.t1136.003
logsource:
  product: aws
  service: cloudtrail
detection:
  create_user:
    eventName: CreateUser
  attach_policy:
    eventName: AttachUserPolicy
    requestParameters.policyArn|contains: 'Administrator'
  timeframe: 10m
  condition: create_user and attach_policy
falsepositives:
  - Legitimate provisioning workflows (CI roles that bootstrap admin accounts)
level: high
KQL (Microsoft Sentinel / Defender / Azure Monitor)
kql
SigninLogs
| where TimeGenerated > ago(1h)
| where ResultType != 0
| summarize FailureCount = count() by UserPrincipalName, IPAddress, bin(TimeGenerated, 5m)
| where FailureCount > 10
| join kind=inner (
    SigninLogs
    | where TimeGenerated > ago(1h)
    | where ResultType == 0
) on UserPrincipalName, IPAddress
| project TimeGenerated, UserPrincipalName, IPAddress, FailureCount

(Failed logons spike on one user/IP, then a success on the same user/IP — classic password spray success.)

SPL (Splunk)
spl
index=aws sourcetype=aws:cloudtrail
  (eventName=CreateUser OR eventName=AttachUserPolicy)
| transaction userIdentity.arn maxspan=10m
| where like(eventName, "%CreateUser%") AND like(eventName, "%AttachUserPolicy%")
| table _time, userIdentity.arn, eventName, requestParameters
ES|QL (Elastic)
esql
FROM logs-aws.cloudtrail-*
| WHERE event.action == "CreateUser" OR event.action == "AttachUserPolicy"
| STATS create_count = COUNT(*) BY user.arn, event.action
| WHERE create_count > 0

(Use the LookML / KQL / SPL / ES|QL that matches your SIEM, but author the canonical version in Sigma.)

Show full SKILL.md (425 more words)Show less
Step 4: Map to MITRE ATT&CK

Every rule should tag at least one ATT&CK technique. Coverage maps roll up to ATT&CK Navigator (navigator.mitre-attack.org):

  • Export your rules with their ATT&CK tags
  • Render onto the Navigator matrix
  • Identify coverage gaps by tactic — "we have nothing for Initial Access via Phishing" is more actionable than "we need more rules"

The Navigator JSON format is open; building this report from your rules-as-code repo is a few hundred lines of Python and pays for itself the first time someone asks "what do we detect?"

Step 5: Tune

The false-positive lifecycle:

  1. Deploy the rule with level: experimental for 1-2 weeks
  2. Review every fire — true positive, false positive, suppressible?
  3. For each FP, ask: can I narrow the rule (more specific filter) or add a tuning exception (allow-list specific known-good)?
  4. Track the ratio — if FPs are > 80% after tuning, the detection model is wrong (signature might need to be statistical, or vice versa). Don't paper over a bad model with 100 allow-list entries.
  5. Promote to level: high / production only after FP rate is acceptable

Rules that have never fired are also a signal — either the log coverage is broken, the query is wrong, or the threat truly hasn't occurred. Verify which by running a deliberate-test event through the system.

Step 6: Detection-as-code

Rules live in Git, not in the SIEM console.

detections/
├── aws/
│   ├── credential-access/
│   │   └── iam-create-user-attach-admin.yml
│   └── ...
├── windows/
├── linux/
└── identity/
    └── okta-password-spray.yml
.github/workflows/
└── detection-ci.yml

CI checks:

  • Sigma validates (sigma-cli check)
  • ATT&CK tag present and resolvable
  • Description and references fields non-empty
  • Backend translation succeeds (sigma convert -t splunk etc.)
  • Optional: replay the rule against a known-good event store and assert hit count

Deployment: post-merge, push rules to the SIEM via API. Roll back via Git revert.

Output Format

Coverage assessment:

markdown
# SIEM Detection Coverage
## Environment: [name]
## Date: [date]

### Log sources mapped
| Source | Status | Notes |
|---|---|---|

### ATT&CK coverage
| Tactic | Techniques covered / total | Blind spots |
|---|---|---|

### Rule inventory
| Rule | ATT&CK | Severity | Status | Last fired |
|------|--------|----------|--------|------------|

### Tuning queue
[Rules in experimental / needing FP triage]

### Recommended next 30 days
[Prioritized — usually 3-5 items]

Per-rule documentation lives with the rule (Sigma YAML), not in a separate runbook. The description, references, and falsepositives fields are the runbook.

Boundaries

  • Detection content for your own environment, or environments where the user has explicit authorization
  • Refuse to write evasion rules or detections designed to flag legitimate security tools
  • Detections that intentionally surveil employees beyond what HR/legal have approved are out of scope — escalate to the user
  • Provide enough context with each rule that the analyst who triages the alert understands what to do; rules without that context produce alert fatigue

References

  • MITRE ATT&CK Enterprise matrix
  • MITRE ATT&CK Navigator
  • Sigma rules repo (SigmaHQ/sigma)
  • Florian Roth's "Detection Engineering" writings
  • Splunk Security Essentials / Microsoft Sentinel content hub / Elastic detection rules repo
  • "Detection Engineering Maturity Matrix" (Florian Roth)
  • "The Pyramid of Pain" (David Bianco) — IOC value hierarchy
  • NIST SP 800-92 (Computer Security Log Management)

© briiirussell, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in skills/siem-detection of briiirussell/cybersecurity-skills.

Open the folder on GitHubat commit c9ade03

Compare with similar skills

Siem Detection next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Siem Detection compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Siem Detection this skillbriiirussell/cybersecurity-skills413—~2.6kAutomated safety check: NotesMIT
Implementing Siem Use Cases For Detectionmukul975/Anthropic-Cybersecurity-Skills34k—~2.8kAutomated safety check: PassApache-2.0
Hunting Threatstrilwu/secskills157—~3.5kAutomated safety check: PassMIT
Detecting Azure Service Principal Abusemukul975/Anthropic-Cybersecurity-Skills34k—~2.1kAutomated safety check: PassApache-2.0
Building Detection Rules With Sigmamukul975/Anthropic-Cybersecurity-Skills34k—~2.7kAutomated safety check: PassApache-2.0
Siem Loggingancoleman/ai-design-components525—~3.4kAutomated safety check: PassMIT

Similar skills

  • Implementing Siem Use Cases For Detection

    mukul975/Anthropic-Cybersecurity-Skills

    Implements SIEM detection use cases by designing correlation rules, threshold alerts, and behavioral analytics mapped to MITRE ATT&CK techniques across Splunk, Elastic, and Sentinel.

    34k GitHub stars~2.8k tokensUpdated 1 mo ago
    SecurityAuto-check passed
  • Hunting Threats

    trilwu/secskills

    Run hypothesis-driven threat hunts across endpoint, network, cloud, and identity telemetry using stack counting, outlier analysis, and ATT&CK-based hypotheses, with SIEM query patterns for Splunk…

    157 GitHub stars~3.5k tokensUpdated 1 mo ago
    SecurityAuto-check passed
  • Detecting Azure Service Principal Abuse

    mukul975/Anthropic-Cybersecurity-Skills

    Detect Azure service principal abuse in Microsoft Entra ID using KQL detection queries (Sentinel/Splunk) against Azure AD Audit and Sign-in Logs, covering added credentials, privileged role…

    34k GitHub stars~2.1k tokensUpdated 1 mo ago
    SecurityAuto-check passed
  • Building Detection Rules With Sigma

    mukul975/Anthropic-Cybersecurity-Skills

    Builds vendor-agnostic detection rules using the Sigma rule format for threat detection across SIEM platforms including Splunk, Elastic, and Microsoft Sentinel.

    34k GitHub stars~2.7k tokensUpdated 1 mo ago
    SecurityAuto-check passed
  • Siem Logging

    ancoleman/ai-design-components

    Configure security information and event management (SIEM) systems for threat detection, log aggregation, and compliance.

    525 GitHub stars~3.4k tokensUpdated 10 mo ago
    SecurityAuto-check passed
  • Detection Sigma

    AgentSecOps/SecOpsAgentKit

    Generic detection rule creation and management using Sigma, the universal SIEM rule format.

    220 GitHub starsUsed in 1 repo~4k tokens
    SecurityAuto-check passed

More from briiirussell/cybersecurity-skills

All 25 skills in this repo
  • AI Risk Management

    briiirussell/cybersecurity-skills

    Apply the NIST AI Risk Management Framework (AI RMF 1.0) and adjacent guidance to AI / ML systems — model lifecycle governance, fairness and bias evaluation, robustness, transparency…

    413 GitHub stars~3.7k tokensUpdated 4 mo ago
    Auto-check: notes
  • API Audit

    briiirussell/cybersecurity-skills

    Audit REST, GraphQL, and RPC APIs against the OWASP API Security Top 10 (2023).

    413 GitHub stars~2.8k tokensUpdated 4 mo ago
    Auto-check: notes
  • Breach Patterns

    briiirussell/cybersecurity-skills

    Learn from public breach disclosures — extract the audit question each one implies and check your own stack.

    413 GitHub stars~3.5k tokensUpdated 4 mo ago
    Auto-check: notes
  • Cloud Audit

    briiirussell/cybersecurity-skills

    Audit cloud infrastructure (AWS, GCP, Azure) for misconfigurations, excessive permissions, and security gaps.

    413 GitHub stars~1.3k tokensUpdated 4 mo ago
    Auto-check: notes
  • Container Audit

    briiirussell/cybersecurity-skills

    Audit container images, Dockerfiles, and Kubernetes manifests for misconfigurations, excessive privileges, exposed secrets, and runtime risks.

    413 GitHub stars~2.5k tokensUpdated 4 mo ago
    Auto-check: notes
  • Crypto Audit

    briiirussell/cybersecurity-skills

    Audit cryptography implementation — algorithm choice, key sizes, KDF parameters, IV/nonce handling, signature verification, randomness, TLS configuration, and key rotation.

    413 GitHub stars~2.8k tokensUpdated 4 mo ago
    Auto-check: notes

Categories

Questions about Siem Detection

What does Siem Detection do?

Engineer and audit SIEM detection rules — log source coverage, Sigma / KQL / SPL / Elastic query authoring, MITRE ATT&CK mapping, false-positive tuning, and detection-as-code workflows. Siem Detection is an agent skill from briiirussell/cybersecurity-skills. Engineer and audit SIEM detection rules — log source coverage, Sigma / KQL / SPL / Elastic query authoring, MITRE ATT&CK mapping, false-positive tuning, and detection-as-code workflows.

When should I use Siem Detection?

Siem Detection fits situations like: the user mentions SIEM; detection engineering; detection rules; detection-as-code.

How do I install Siem Detection in Claude Code?

Run `npx skills add briiirussell/cybersecurity-skills --skill siem-detection -a claude-code`. Or copy the skill folder (skills/siem-detection in briiirussell/cybersecurity-skills) into .claude/skills/siem-detection in your project. Claude Code loads it when a task matches its description.

How do I install Siem Detection in Codex?

Run `npx skills add briiirussell/cybersecurity-skills --skill siem-detection -a codex`. Or copy the skill folder (skills/siem-detection in briiirussell/cybersecurity-skills) into .agents/skills/siem-detection in your project. Codex loads it when a task matches its description.

Can I use Siem Detection in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add briiirussell/cybersecurity-skills --skill siem-detection -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/siem-detection, .gemini/skills/siem-detection, .github/skills/siem-detection and .opencode/skills/siem-detection in your project.

What does Siem Detection need to run?

SKILL.md names no scripts, command-line tools or credentials: Siem Detection is instructions for the agent only. Our summary lists: Python 3. Its frontmatter pre-approves these tools: Read, Write, Bash, Grep, Glob, WebSearch.

Does Siem Detection access the network?

SKILL.md names 1 domain. In commands or code: attack.mitre.org; the agent is likely to contact it when it follows the instructions. This is read from the text; nothing was executed.

Is Siem Detection safe to install?

Our automated static check of SKILL.md found notes only (pre-approves every shell command (allowed-tools: bash)), nothing it rates as a warning. It is not a guarantee. Review the folder before installing.

What licence does Siem Detection use?

Siem Detection is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Siem Detection use?

About 2.6k tokens (SKILL.md is roughly 10k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Siem Detection?

Skills that share tags, products or a category with Siem Detection: Implementing Siem Use Cases For Detection (mukul975/Anthropic-Cybersecurity-Skills, 34k stars), Hunting Threats (trilwu/secskills, 157 stars), Detecting Azure Service Principal Abuse (mukul975/Anthropic-Cybersecurity-Skills, 34k stars) and Building Detection Rules With Sigma (mukul975/Anthropic-Cybersecurity-Skills, 34k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Siem Detection?

briiirussell (a GitHub user) maintains it in briiirussell/cybersecurity-skills, which has 413 GitHub stars. The repository holds 25 skills in this directory. The repository was last updated on May 27, 2026.

Source: briiirussell/cybersecurity-skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.