Agent skill

Sigma Detection Engineer

by criptogus in criptogus/agent-evolve-network

Turns a described threat behavior or log sample into a validated Sigma detection rule with MITRE ATT&CK mapping, false-positive notes and a test plan.

Apache-2.0Auto-check passedTesting & QA

Install Sigma Detection Engineer

skills CLI
$ npx skills add criptogus/agent-evolve-network --skill sigma-detection-engineer -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install criptogus/agent-evolve-network sigma-detection-engineer --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/criptogus/agent-evolve-network.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/sigma-detection-engineer .claude/skills/sigma-detection-engineer && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
sigma-detection-engineer
GitHub stars
288
Token cost
~1.2k tokens
SKILL.md length
386 words
Files
1
Skills in repo
107
Repo updated
First seen
Licence
Apache-2.0

At a glance

Turns a described threat behavior or log sample into a validated Sigma detection rule with MITRE ATT&CK mapping, false-positive notes and a test plan.

  • The user asks for sigma detection engineer work
  • SKILL.md covers Instructions, Always, Never and Input / output contract, plus 1 more section
  • Reaches superagentskill.com
  • Tasks that involve Test generation

What it does

Sigma Detection Engineer is an agent skill from criptogus/agent-evolve-network. Turns a described threat behavior or log sample into a validated Sigma detection rule with MITRE ATT&CK mapping, false-positive notes and a test plan. Use when the user asks for sigma detection engineer work, or mentions sigma, detection, engineer.

Its SKILL.md is about 1.2k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Testing & QA, covering Test generation. The licence is Apache-2.0.

When your agent uses it

  • The user asks for sigma detection engineer work
  • Tasks that involve Test generation

Example prompts

  • “Use the sigma-detection-engineer skill to turn a described threat behavior or log sample into a validated Sigma detection rule with MITRE ATT&CK…”
  • “/sigma-detection-engineer”

Requirements

  • Node.js

What it can do on your machine

Read from SKILL.md and the folder at commit d19b920. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md (its code samples are json).

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Hosts in commands or code, which the agent is likely to contact:

    • superagentskill.com

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Sigma Detection Engineer loads about 1.2k tokens when it runs. Until then it costs about 68 tokens; SKILL.md has 386 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~68
When it runs · the whole SKILL.md, loaded when a task matches
~1.2k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from criptogus/agent-evolve-network at commit d19b920, republished under its Apache-2.0 licence (© criptogus). 386 words, ~1,224 tokens.

Download SKILL.mdSave it as .claude/skills/sigma-detection-engineer/SKILL.md (or your agent's skills folder).
name
sigma-detection-engineer
description
Turns a described threat behavior or log sample into a validated Sigma detection rule with MITRE ATT&CK mapping, false-positive notes and a test plan. Use when the user asks for sigma detection engineer work, or mentions sigma, detection, engineer.
version
0.1.0
license
Apache-2.0
homepage
https://superagentskill.com/marketplace/sigma-detection-engineer
source
Super Agent Skill (SAK)

Sigma Detection Engineer

Use when you have a log source (Windows Event Log, Sysmon, cloud audit, EDR, proxy) and a behavior you want to detect, and you need a portable Sigma rule rather than a vendor-locked query. Produces a syntactically valid Sigma rule, the ATT&CK technique it covers, expected false positives, tuning guidance and a concrete test to fire it. Does NOT deploy rules, query live SIEMs, or claim coverage it cannot justify from the provided telemetry.

Adapted for Super Agent Skill from the open Anthropic-Cybersecurity-Skills corpus (Apache-2.0); restructured into a typed input -> output contract and hardened for adversarial review.

Instructions

You are a detection engineer who writes portable Sigma rules. Given a log source and a target behavior, output: (1) a valid Sigma rule in YAML (title, status, logsource, detection, condition, level, tags), (2) the MITRE ATT&CK technique id(s) it detects, (3) likely false positives and how to tune them, (4) a test that triggers the rule. Anchor every selection field to a real field name from the provided log sample or a named, standard log source. Prefer high-signal selections over brittle string matches. If the provided telemetry cannot support a reliable rule, say so and state what additional logging is required instead of inventing fields.

Always

  • Emit syntactically valid Sigma (logsource + detection + condition).
  • Map the rule to at least one MITRE ATT&CK technique id.
  • List concrete false positives and a tuning lever for each.
  • Only reference log fields present in the sample or in the named standard source.
Show full SKILL.md (136 more words)Show less

Never

  • Invent field names or log sources not supported by the input.
  • Claim detection coverage for techniques the rule does not actually match.
  • Output a vendor-proprietary query in place of Sigma unless explicitly asked.

Input / output contract

Input:

json
{
  "type": "object",
  "properties": {
    "log_source": {
      "type": "string"
    },
    "behavior": {
      "type": "string"
    },
    "sample_event": {
      "type": "string"
    }
  },
  "required": [
    "log_source",
    "behavior"
  ]
}

Output:

json
{
  "type": "object",
  "properties": {
    "sigma_rule": {
      "type": "string"
    },
    "attack_techniques": {
      "type": "array",
      "items": {
        "type": "string"
      }
    },
    "false_positives": {
      "type": "array",
      "items": {
        "type": "string"
      }
    },
    "test_plan": {
      "type": "string"
    }
  },
  "required": [
    "sigma_rule",
    "attack_techniques"
  ]
}

Examples

Detect Kerberoasting from Windows Security log

Input:

log_source: windows-security
behavior: Kerberoasting — many TGS (4769) requests with RC4 encryption for service accounts.

Expected output:

```yaml
title: Potential Kerberoasting via RC4 TGS Requests
status: experimental
logsource:
  product: windows
  service: security
detection:
  selection:
    EventID: 4769
    TicketEncryptionType: '0x17'
  filter:
    ServiceName|endswith: '$'
  condition: selection and not filter
level: medium
tags:
  - attack.credential_access
  - attack.t1558.003

ATT&CK: T1558.003 (Kerberoasting). False positives: legacy apps that still negotiate RC4 — tune by allow-listing known service accounts in filter. Test: request a TGS for a SPN-enabled service account using RC4 and confirm the rule fires.


### Insufficient telemetry

Input:

log_source: firewall-allow-logs behavior: detect in-memory .NET assembly load


Expected output:

Firewall allow logs cannot observe in-process .NET assembly loads. No reliable Sigma rule is possible from this source. Required logging: Sysmon Event ID 7 (Image/Module load) or ETW Microsoft-Windows-DotNETRuntime CLR load events. ATT&CK target would be T1620 (Reflective Code Loading) once that telemetry exists.


## Trust & telemetry

This skill is graded on the Super Agent Skill network: format, substance and adversarial
(prompt-injection) testing produce a public Trust Score.

- Trust Score & evidence: https://superagentskill.com/marketplace/trust/sigma-detection-engineer
- Skill page: https://superagentskill.com/marketplace/sigma-detection-engineer
- Live version (always current) via MCP: https://superagentskill.com/api/mcp

Reinstall or update with `npx skills update`, or pull the live graded version with
`npx super-agent install sigma-detection-engineer`.

© criptogus, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in skills/sigma-detection-engineer of criptogus/agent-evolve-network.

Open the folder on GitHubat commit d19b920

Compare with similar skills

Sigma Detection Engineer next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Sigma Detection Engineer compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Sigma Detection Engineer this skillcriptogus/agent-evolve-network288—~1.2kAutomated safety check: PassApache-2.0
Emcaklofas/kicad-happy1.4k1 repos~2.8kAutomated safety check: PassMIT
Swig Testswig/swig6.3k—~2.3kAutomated safety check: PassCustom licence
Generate Test Cases342164796/generate-test-cases1191 repos~2.9kAutomated safety check: PassNone
Verify Cc Safety Netkenryu42/cc-safety-net1.6k—~2kAutomated safety check: PassMIT
Wioworkersio/skills190—~5.8kAutomated safety check: PassMIT

Similar skills

  • Emc

    aklofas/kicad-happy

    EMC pre-compliance risk analysis for KiCad PCB designs — 18 check categories, 44 rule IDs covering ground planes, decoupling, I/O filtering, switching harmonics, clock routing, differential pair…

    1.4k GitHub starsUsed in 1 repo~2.8k tokens
    Testing & QAAuto-check passed
  • Swig Test

    swig/swig

    Run SWIG test suite for specific languages. An agent skill from swig/swig.

    6.3k GitHub stars~2.3k tokensUpdated yesterday
    Testing & QAAuto-check passed
  • Generate Test Cases

    342164796/generate-test-cases

    自主学习型测试文档生成器。从需求文档(Markdown)生成测试用例 XMind 文件,支持持久化记忆和持续学习。当用户提到"生成测试用例"、"根据需求生成测试"时触发。

    119 GitHub starsUsed in 1 repo~2.9k tokens
    Testing & QAAuto-check passed
  • Verify Cc Safety Net

    kenryu42/cc-safety-net

    Launch and drive the real cc-safety-net CLI — the hook decision path, explain, status/doctor, logs, and the local policy GUI — against an isolated home, capturing evidence.

    1.6k GitHub stars~2k tokensUpdated today
    Testing & QAAuto-check passed
  • Wio

    workersio/skills

    Testing workflow skill for finding high-value test candidates, writing focused tests, generating realistic workloads, reviewing test value, and diagnosing test-suite health.

    190 GitHub stars~5.8k tokensUpdated 2 mo ago
    Testing & QAAuto-check passed
  • File Server

    microsoft/WindowsProtocolTestSuites

    Official

    ALWAYS LOAD THIS SKILL when working with FileServer, SMB, SMB2, SMB3, CIFS, file sharing, MS-SMB2, MS-FSCC, MS-FSA, MS-DFSC, MS-FSRVP, MS-RSVD, MS-SQOS, or any file server protocol test…

    567 GitHub stars~4.1k tokensUpdated 22 days ago
    Testing & QAAuto-check passed

More from criptogus/agent-evolve-network

All 107 skills in this repo
  • Brand Research

    criptogus/agent-evolve-network

    Kickoff research for a brand you haven't worked on before — web research, existing-ad analysis from the Meta Ad Library, editorial-grammar profiling, sourced + AI-generated brand assets, hook/CTA…

    288 GitHub stars~3.9k tokensUpdated 28 days ago
    Auto-check passed
  • Create Apple Notes Video Ad

    criptogus/agent-evolve-network

    Produce a 9:16 social-native ad recreating the iPhone Apple Notes typing experience — the note begins with 1–2 visible lines, then progressively types additional paragraphs character-by-character…

    288 GitHub stars~4.9k tokensUpdated 28 days ago
    Auto-check passed
  • Create Chatgpt Video Ad

    criptogus/agent-evolve-network

    Produce a 9:16 social-native ad that recreates a ChatGPT mobile chat — user types in the composer with the iOS keyboard visible, taps send, keyboard slides down, header right-cluster swaps…

    288 GitHub stars~5k tokensUpdated 28 days ago
    Auto-check passed
  • Create Imessage Video Ad

    criptogus/agent-evolve-network

    Produce a 9:16 social-native ad that recreates an iMessage conversation reveal — bubbles pop in over time, composer types char-by-char, real Apple iMessage SFX hit on every send/receive, music bed…

    288 GitHub stars~7.4k tokensUpdated 28 days ago
    Auto-check passed
  • Cloud Misconfig Auditor

    criptogus/agent-evolve-network

    Audits AWS, GCP and Azure environments (and matching IaC) for excessive permissions, public exposure, weak encryption defaults and missing logging.

    288 GitHub stars~965 tokensUpdated 28 days ago
    Auto-check passed
  • Cloudflare Workers Expert

    criptogus/agent-evolve-network

    Builds and debugs Cloudflare Workers, Durable Objects, KV, R2, D1, and Queues with edge-correct patterns.

    288 GitHub stars~619 tokensUpdated 28 days ago
    Auto-check passed

Categories

Questions about Sigma Detection Engineer

What does Sigma Detection Engineer do?

Turns a described threat behavior or log sample into a validated Sigma detection rule with MITRE ATT&CK mapping, false-positive notes and a test plan. Sigma Detection Engineer is an agent skill from criptogus/agent-evolve-network. Turns a described threat behavior or log sample into a validated Sigma detection rule with MITRE ATT&CK mapping, false-positive notes and a test plan.

When should I use Sigma Detection Engineer?

Sigma Detection Engineer fits situations like: the user asks for sigma detection engineer work; tasks that involve Test generation.

How do I install Sigma Detection Engineer in Claude Code?

Run `npx skills add criptogus/agent-evolve-network --skill sigma-detection-engineer -a claude-code`. Or copy the skill folder (skills/sigma-detection-engineer in criptogus/agent-evolve-network) into .claude/skills/sigma-detection-engineer in your project. Claude Code loads it when a task matches its description.

How do I install Sigma Detection Engineer in Codex?

Run `npx skills add criptogus/agent-evolve-network --skill sigma-detection-engineer -a codex`. Or copy the skill folder (skills/sigma-detection-engineer in criptogus/agent-evolve-network) into .agents/skills/sigma-detection-engineer in your project. Codex loads it when a task matches its description.

Can I use Sigma Detection Engineer in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add criptogus/agent-evolve-network --skill sigma-detection-engineer -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/sigma-detection-engineer, .gemini/skills/sigma-detection-engineer, .github/skills/sigma-detection-engineer and .opencode/skills/sigma-detection-engineer in your project.

What does Sigma Detection Engineer need to run?

SKILL.md names no scripts, command-line tools or credentials: Sigma Detection Engineer is instructions for the agent only. Our summary lists: Node.js.

Does Sigma Detection Engineer access the network?

SKILL.md names 1 domain. In commands or code: superagentskill.com; the agent is likely to contact it when it follows the instructions. This is read from the text; nothing was executed.

Is Sigma Detection Engineer safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Sigma Detection Engineer use?

Sigma Detection Engineer is published under the Apache-2.0 licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Sigma Detection Engineer use?

About 1.2k tokens (SKILL.md is roughly 4.9k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Sigma Detection Engineer?

Skills that share tags, products or a category with Sigma Detection Engineer: Emc (aklofas/kicad-happy, 1.4k stars), Swig Test (swig/swig, 6.3k stars), Generate Test Cases (342164796/generate-test-cases, 119 stars) and Verify Cc Safety Net (kenryu42/cc-safety-net, 1.6k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Sigma Detection Engineer?

criptogus (a GitHub user) maintains it in criptogus/agent-evolve-network, which has 288 GitHub stars. The repository holds 107 skills in this directory. The repository was last updated on September 9, 2026.

Source: criptogus/agent-evolve-network on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.