detection-engineering

Installation
SKILL.md

Detection engineering — OpenTide + DetectionOps

This skill governs how detection content moves through its lifecycle. It pairs OpenTide's object lineage (Threat Vector → Detection Objective → Detection Rule) with the practical mechanics of converting validated hunting queries into production-grade detection rules on the platforms CoreTide deploys to.

Always pair with: language skills (kusto-query-language, splunk-spl-processing), platform skills (microsoft-sentinel, microsoft-defender-endpoint, crowdstrike-falcon, carbon-black-cloud, sentinelone-singularity, harfanglab), and the OpenTide object skills (opentide-threat-vector, opentide-detection-objective, opentide-detection-rule).


1. OpenTide sequencing

  1. Evidence / threat modelling — opentide-threat-vector (TVM YAML, Phase A intel structuring + Phase B authoring).
  2. Detection intent & signals — opentide-detection-objective (DOM YAML, signals, data contracts, methodology).
  3. Deployable artefacts — opentide-detection-rule (MDR YAML, plus platform-specific configurations.* blocks).

Default rule: one object type per change request unless explicitly running an end-to-end vertical slice (drill, pilot deployment, framework-bootstrap).

CoreTide-aligned configuration keys most commonly seen:

Installs
3
First Seen
Sep 16, 2026