Security Alert Triage
elastic/agent-skills
Triage Elastic Security alerts — gather context, classify threats, create cases, and acknowledge.
Author and maintain Sigma detection rules — structure, logsource taxonomy, detection logic with modifiers, false-positive filtering, backend conversion with pySigma, and offline validation with…
$ npx skills add trilwu/secskills --skill writing-sigma-rules -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install trilwu/secskills writing-sigma-rules --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/trilwu/secskills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/secskills-defense/skills/writing-sigma-rules .claude/skills/writing-sigma-rules && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "writing-sigma-rules" agent skill from https://github.com/trilwu/secskills/tree/main/secskills-defense/skills/writing-sigma-rules into .claude/skills/writing-sigma-rules/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "writing-sigma-rules", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/trilwu/secskills/tree/main/secskills-defense/skills/writing-sigma-rulesType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add trilwu/secskills --skill writing-sigma-rules -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install trilwu/secskills writing-sigma-rules --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/trilwu/secskills.git skills-src && mkdir -p .agents/skills && cp -r skills-src/secskills-defense/skills/writing-sigma-rules .agents/skills/writing-sigma-rules && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "writing-sigma-rules" agent skill from https://github.com/trilwu/secskills/tree/main/secskills-defense/skills/writing-sigma-rules into .agents/skills/writing-sigma-rules/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "writing-sigma-rules", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add trilwu/secskills --skill writing-sigma-rules -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install trilwu/secskills writing-sigma-rules --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/trilwu/secskills.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/secskills-defense/skills/writing-sigma-rules .cursor/skills/writing-sigma-rules && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "writing-sigma-rules" agent skill from https://github.com/trilwu/secskills/tree/main/secskills-defense/skills/writing-sigma-rules into .cursor/skills/writing-sigma-rules/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "writing-sigma-rules", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/trilwu/secskills.git --path secskills-defense/skills/writing-sigma-rules--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add trilwu/secskills --skill writing-sigma-rules -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install trilwu/secskills writing-sigma-rules --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/trilwu/secskills.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/secskills-defense/skills/writing-sigma-rules .gemini/skills/writing-sigma-rules && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "writing-sigma-rules" agent skill from https://github.com/trilwu/secskills/tree/main/secskills-defense/skills/writing-sigma-rules into .gemini/skills/writing-sigma-rules/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "writing-sigma-rules", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install trilwu/secskills writing-sigma-rulesInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add trilwu/secskills --skill writing-sigma-rules -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/trilwu/secskills.git skills-src && mkdir -p .github/skills && cp -r skills-src/secskills-defense/skills/writing-sigma-rules .github/skills/writing-sigma-rules && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "writing-sigma-rules" agent skill from https://github.com/trilwu/secskills/tree/main/secskills-defense/skills/writing-sigma-rules into .github/skills/writing-sigma-rules/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "writing-sigma-rules", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add trilwu/secskills --skill writing-sigma-rules -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install trilwu/secskills writing-sigma-rules --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/trilwu/secskills.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/secskills-defense/skills/writing-sigma-rules .opencode/skills/writing-sigma-rules && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "writing-sigma-rules" agent skill from https://github.com/trilwu/secskills/tree/main/secskills-defense/skills/writing-sigma-rules into .opencode/skills/writing-sigma-rules/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "writing-sigma-rules", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
writing-sigma-rulesAuthor and maintain Sigma detection rules — structure, logsource taxonomy, detection logic with modifiers, false-positive filtering, backend conversion with pySigma, and offline validation with…
Writing Sigma Rules is an agent skill from trilwu/secskills. Author and maintain Sigma detection rules — structure, logsource taxonomy, detection logic with modifiers, false-positive filtering, backend conversion with pySigma, and offline validation with Hayabusa or Chainsaw. Use when translating threat intel into vendor-agnostic detection logic, building a detection-as-code pipeline around Sigma, reviewing or tuning existing Sigma rules, or converting rules across SIEM backends.
Its SKILL.md is about 4.1k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.
It sits in Security, covering Security operations and Translation. The repository describes itself as: Transform Claude Code into your personal security engineer. The licence is MIT.
5 steps, taken from the first numbered list in SKILL.md.
Read from SKILL.md and the folder at commit ca53957. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Shell commands in SKILL.md call:
pipcurlFrom the folder's file list and the shell code blocks in SKILL.md.
Hosts in commands or code, which the agent is likely to contact:
attack.mitre.orgdefuddle.mdFrom URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Writing Sigma Rules loads about 4.1k tokens when it runs. Until then it costs about 111 tokens; SKILL.md has 1,427 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from trilwu/secskills at commit ca53957, republished under its MIT licence (© trilwu). 1,427 words, ~4,077 tokens.
.claude/skills/writing-sigma-rules/SKILL.md (or your agent's skills folder).Sigma is the common language for detection logic -- write once, convert to any SIEM. The value is portability and reviewability, but only if the rule is precise: a Sigma rule that matches everything is worse than no rule, because it consumes analyst time and trains the team to ignore alerts. The work is specificity without brittleness.
engineering-detectionswriting-yara-ruleshunting-threatsresponding-to-incidentsEvery rule is a YAML document with these fields in order:
The specification requires only three fields: title, logsource, and
detection (which must contain a condition). Everything else is optional
to the spec. Do not confuse that with the SigmaHQ rule repository, which
requires far more — id, status, description, author, date, level,
and ATT&CK tags — before it will accept a contribution. Write to the stricter
SigmaHQ convention by default, because a rule without an id or a level is
unmanageable in a real pipeline, but know which constraint you are meeting when
a converter accepts a rule your reviewer rejects.
title: Short Descriptive Name # REQUIRED by spec, max ~100 chars
id: a1b2c3d4-0000-4000-8000-000000000001 # optional to spec; UUIDv4, never reuse
related: # optional, link to predecessor rules
- id: <uuid>
type: derived | obsoletes | merged | renamed | similar
status: experimental # optional; see lifecycle below
description: > # optional to spec, expected by SigmaHQ
Detects X behaviour consistent with Y technique.
references: # optional, strongly recommended
- https://attack.mitre.org/techniques/T1059/001/
author: Your Name # optional to spec
date: 2026-07-26 # optional; ISO 8601 YYYY-MM-DD
modified: 2026-07-26 # optional; same format, on update
tags: # optional to spec, expected by SigmaHQ
- attack.execution # tactic (lowercase, dotted)
- attack.t1059.001 # technique (lowercase)
logsource: # REQUIRED by spec
category: process_creation
product: windows
detection: # REQUIRED by spec
selection:
CommandLine|contains: 'some-indicator'
condition: selection # REQUIRED inside detection
falsepositives: # optional to spec
- Legitimate admin scripts using the same flag
level: medium # optional; informational|low|medium|high|criticalDate format. The spec mandates ISO 8601 with hyphens — YYYY-MM-DD. Older
rules and much online material use the legacy YYYY/MM/DD; that form is
outdated, and some tooling now rejects it.
Status lifecycle. The permitted values are experimental, test,
stable, deprecated, and unsupported. In practice: experimental =
observation only, no alerting. test = validated against emulation, ready for
limited deployment. stable = tuned in production with documented FPs.
deprecated = replaced, no longer accurate. unsupported = not usable as
written (e.g. depends on homemade fields). Never promote without the
corresponding work.
The logsource block abstracts the data source. Specify only what is needed.
Categories: process_creation, file_event, file_access,
network_connection, registry_event, dns_query, image_load,
pipe_created, process_access, driver_load, create_remote_thread.
Product: windows, linux, macos.
Service: sysmon, security, system, powershell, powershell-classic,
application, taskscheduler, windefend, firewall-as.
Use category when you care about the event type regardless of collection
method. Use product + service when targeting a specific log channel.
Do not combine category and service unless the backend requires it.
Define what to match (selection), what to exclude (filter_*), combine in
condition:
detection:
selection:
ParentImage|endswith: '\explorer.exe'
CommandLine|contains|all:
- 'powershell'
- '-enc'
filter_legitimate:
CommandLine|contains: 'company-deploy-script'
User|startswith: 'SVC_'
condition: selection and not filter_legitimatecondition: selection # simple match
condition: selection and not filter # match minus exclusions
condition: selection1 or selection2 # either pattern
condition: (sel1 and sel2) and not (fp1 or fp2)
condition: all of selection* # all blocks starting with "selection"
condition: 1 of selection* # any one blockMatch against the full log event (all fields). Blunt instrument -- prefer field-specific selections for production rules:
detection:
keywords:
- 'Invoke-Mimikatz'
- 'sekurlsa::logonpasswords'
condition: keywordsChain with |. Example: CommandLine|contains|all.
| Modifier | Effect |
|---|---|
contains | Substring match |
startswith / endswith | Prefix / suffix match |
re | Regular expression (PCRE) |
base64offset | Match base64-encoded variants at all three offsets |
all | All list values must match (default is any) |
cidr | CIDR network range match on IP fields |
windash | Match both - and / as argument prefix |
expand | Expand environment variables like %SystemRoot% |
wide / utf16le / utf16be / utf16 | Match the wide (UTF-16) encoding of the value; wide is an alias for utf16le. There is no utf8 modifier |
exists | Field present (true) or absent (false) |
detection:
selection:
CommandLine|contains|windash|all: ['bypass', 'hidden', 'noprofile']
filter_admin:
ParentImage|endswith: ['\sccm.exe', '\intune_agent.exe']
condition: selection and not filter_admindetection:
selection:
ParentImage|endswith: '\winword.exe'
Image|endswith: ['\cmd.exe', '\powershell.exe', '\wscript.exe', '\mshta.exe']
condition: selectiondetection:
selection:
TargetFilename|contains: ['\AppData\Local\Temp\', '\ProgramData\', '\Users\Public\']
TargetFilename|endswith: ['.exe', '.dll', '.scr', '.hta']
condition: selectiondetection:
selection:
TargetObject|contains: ['\CurrentVersion\Run\', '\CurrentVersion\RunOnce\']
EventType: SetValue
filter_installers:
Image|startswith: 'C:\Windows\Installer\'
condition: selection and not filter_installersdetection:
selection:
PipeName: ['\MSSE-*', '\postex_*', '\msagent_*', '\status_*']
condition: selectionWMI: logsource product: windows, service: sysmon, match EventID: 21,
Operation: Created. Scheduled tasks: logsource category: process_creation,
match Image|endswith: '\schtasks.exe' with CommandLine|contains|all: ['/create', '/sc'], filter on SYSTEM + known management tools.
Exclusions go in named filter_* blocks, never inline with the selection.
Use condition: selection and not 1 of filter_* to apply all filters.
Filter on properties the attacker cannot control: full file paths of signed vendor binaries (not filenames alone), service account SIDs (not usernames), parent-child pairs from specific software workflows, verified certificate subjects. Never filter on filenames alone, attacker-controllable command-line fragments, or hostnames without justification.
| Level | Response expectation |
|---|---|
informational | Automated tagging, correlation input only |
low | Batch review, daily triage |
medium | Analyst queue, investigate within hours |
high | Prompt investigation, likely malicious |
critical | Immediate response, active compromise |
Set level based on expected TP rate and business impact, not on how dangerous
the technique sounds. A noisy critical rule causes more damage than a
precise medium one.
When a single event is too common to alert on, use Sigma correlation rules
that reference other rules by ID, group by a field (e.g., ComputerName),
and require a threshold within a time window:
title: Correlation - Multiple Suspicious Events from Same Host
type: correlation
rules:
- id: <uuid-of-rule-1>
- id: <uuid-of-rule-2>
group-by: [ComputerName]
timespan: 15m
condition:
gte: 2
level: highpip install sigma-cli pySigma-backend-splunk pySigma-backend-elasticsearch \
pySigma-backend-kusto pySigma-backend-qradar
sigma convert -t splunk -p sysmon rules/rule.yml
sigma convert -t elasticsearch -p ecs_windows rules/rule.yml
sigma convert -t kusto -p microsoft_xdr rules/rule.yml
sigma convert -t qradar rules/rule.yml
sigma convert -t splunk -p sysmon rules/ # entire directory
sigma convert -t splunk -p sysmon -f savedsearches rules/ # output format| Backend | Common pipelines |
|---|---|
| Splunk | sysmon, splunk_windows, splunk_cim |
| Elastic | ecs_windows, ecs_zeek, filebeat |
| Sentinel/XDR | microsoft_xdr, azure_monitor |
| CrowdStrike | crowdstrike |
| Chronicle | chronicle_default |
Always verify converted output against your actual field names. Pipeline defaults may not match custom parsing configurations.
sigma check rules/rule.yml # single rule
sigma check rules/ # entire directoryCommon failures: missing or duplicate id, invalid level, malformed YAML,
undefined modifier, empty detection block.
hayabusa csv-timeline -d ./sample_evtx/ -r rules/rule.yml
chainsaw hunt ./sample_evtx/ -s rules/rule.yml --mapping mappings/sigma-mapping.ymlfalsepositives field and the PR description.SigmaHQ requirements: valid UUIDv4 id; status set appropriately
(experimental for new); date/modified in YYYY/MM/DD; at least one
ATT&CK tag; non-empty falsepositives (even Unknown); level based on TP
rate; descriptive description; references linking to source intel.
YAML formatting: two-space indent, no tabs; pipe-separated modifiers
without spaces (field|contains|all); dash-space lists; single-quoted strings
with special characters; folded scalar (>) for long descriptions; one rule
per file, snake_case filename matching the title.
Field naming: use Sigma standard names (Image, ParentImage,
CommandLine, User, TargetFilename, TargetObject, DestinationIp,
DestinationPort, SourceIp, PipeName, Hashes). Backend conversion
handles translation. Writing backend-specific field names defeats portability.
Tag compliance: attack.<tactic> (lowercase, hyphenated) and
attack.t<number> (lowercase, dotted sub-technique). Add cve.YYYY.NNNNN
when applicable. Verify IDs against the current ATT&CK release -- stale IDs
from retired techniques create mapping errors downstream.
Fetch public advisories, specifications, and vendor reports as Markdown:
curl -sL "https://defuddle.md/<url>" # scheme in the path is optionalThis strips page boilerplate — roughly 78% fewer tokens on a prose page — and returns the full text rather than a summary, so you can grep it and trust a negative result.
Three things it is not for. Fetch JSON and API responses raw, because readability extraction mangles structured data. Fetch authenticated or JavaScript-rendered pages directly, because it retrieves them anonymously. And never route adversary infrastructure (phishing links, C2, malware hosting), client-owned hosts, or engagement URLs through it — the request leaves your machine to a third party, and for live adversary infrastructure it also tips off the operator.
Some sites block the extractor and return an error blob rather than the page —
{"error":"Failed to fetch: 418 I'm a teapot"} from freedesktop.org, for
instance. That is the fetch being refused, not the source saying the thing
does not exist. Re-fetch the URL directly before drawing any conclusion from
it.
engineering-detections -- the full detection lifecycle including YARA, Suricata, and coverage measurementhunting-threats -- hypothesis-driven hunting that produces the findings rules are built frommapping-attack-techniques -- ATT&CK technique resolution and the purple-team loopreporting-security-findings -- writing up what the detection found© trilwu, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
Just SKILL.md in secskills-defense/skills/writing-sigma-rules of trilwu/secskills.
Open the folder on GitHubat commit ca53957
Writing Sigma Rules next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Writing Sigma Rules this skilltrilwu/secskills | 157 | — | ~4.1k | Automated safety check: Pass | MIT | |
| Security Alert Triageelastic/agent-skills | 592 | 1 repos | ~3.5k | Automated safety check: Notes | Apache-2.0 | |
| Kubernetes Network Security Auditkubeshark/kubeshark | 12k | — | ~7.3k | Automated safety check: Notes | Apache-2.0 | |
| Security Detection Rule Managementelastic/agent-skills | 592 | 1 repos | ~3.9k | Automated safety check: Notes | Apache-2.0 | |
| Vbs Scan Securitytanviet12/vbsec | 289 | — | ~5.3k | Automated safety check: Notes | MIT | |
| Chaitin CLIchaitin/chaitin-cli | 115 | — | ~15k | Automated safety check: Notes | GPL-3.0 |
elastic/agent-skills
Triage Elastic Security alerts — gather context, classify threats, create cases, and acknowledge.
kubeshark/kubeshark
Hunts for compromised workloads and malicious traffic in a Kubernetes cluster by sweeping network data through Kubeshark MCP, mapped to MITRE ATT&CK.
elastic/agent-skills
Create, tune, and manage Elastic Security detection rules (SIEM and Endpoint).
tanviet12/vbsec
A skill your agent uses when scanning code for security vulnerabilities.
chaitin/chaitin-cli
A skill your agent uses when running chaitin-cli commands to manage Chaitin security products: SafeLine WAF (site management, IP blocking, ACL, policy rules, attack logs), X-Ray vulnerability…
Nebulock-Inc/agentic-threat-hunting-framework
GATES method validation for hunt-derived detections. An agent skill from Nebulock-Inc/agentic-threat-hunting-framework.
trilwu/secskills
Audit source code for exploitable vulnerabilities using threat-model-driven review, taint tracing, invariant checking, and variant analysis.
trilwu/secskills
Perform OSINT, subdomain enumeration, port scanning, web reconnaissance, email harvesting, and cloud asset discovery for initial access.
trilwu/secskills
Assess and harden LLM applications and agentic systems against prompt injection, tool misuse, excessive agency, memory poisoning, RAG data leakage, and model supply-chain risk, mapped to the OWASP…
trilwu/secskills
Reverse engineer compiled binaries, firmware, and mobile app packages using triage, static disassembly, decompilation, and dynamic instrumentation.
trilwu/secskills
Reverse engineer Go binaries by recovering function names and types from pclntab and moduledata using GoReSym, redress, and IDA/Ghidra Go plugins, and by reading Go's non-standard calling…
trilwu/secskills
Analyze iOS applications at the binary level — decrypting FairPlay-protected IPAs with frida-ios-dump or bagbak, inspecting Mach-O load commands, recovering Objective-C headers with class-dump, and…
Categories
Author and maintain Sigma detection rules — structure, logsource taxonomy, detection logic with modifiers, false-positive filtering, backend conversion with pySigma, and offline validation with…. Writing Sigma Rules is an agent skill from trilwu/secskills. Author and maintain Sigma detection rules — structure, logsource taxonomy, detection logic with modifiers, false-positive filtering, backend conversion with pySigma, and offline validation with Hayabusa or Chainsaw.
Writing Sigma Rules fits situations like: translating threat intel into vendor-agnostic detection logic; building a detection-as-code pipeline around Sigma; tuning existing Sigma rules; converting rules across SIEM backends.
Run `npx skills add trilwu/secskills --skill writing-sigma-rules -a claude-code`. Or copy the skill folder (secskills-defense/skills/writing-sigma-rules in trilwu/secskills) into .claude/skills/writing-sigma-rules in your project. Claude Code loads it when a task matches its description.
Run `npx skills add trilwu/secskills --skill writing-sigma-rules -a codex`. Or copy the skill folder (secskills-defense/skills/writing-sigma-rules in trilwu/secskills) into .agents/skills/writing-sigma-rules in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add trilwu/secskills --skill writing-sigma-rules -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/writing-sigma-rules, .gemini/skills/writing-sigma-rules, .github/skills/writing-sigma-rules and .opencode/skills/writing-sigma-rules in your project.
Going by SKILL.md and its folder, Writing Sigma Rules needs the command-line tools its instructions call (pip and curl). Our summary lists: Python 3.
SKILL.md names 2 domains. In commands or code: attack.mitre.org and defuddle.md; the agent is likely to contact these when it follows the instructions. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
Writing Sigma Rules is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 4.1k tokens (SKILL.md is roughly 16k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with Writing Sigma Rules: Security Alert Triage (elastic/agent-skills, 592 stars), Kubernetes Network Security Audit (kubeshark/kubeshark, 12k stars), Security Detection Rule Management (elastic/agent-skills, 592 stars) and Vbs Scan Security (tanviet12/vbsec, 289 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
trilwu (a GitHub user) maintains it in trilwu/secskills, which has 157 GitHub stars. The repository holds 50 skills in this directory. The repository was last updated on September 4, 2026.
Source: trilwu/secskills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.