detection-engineering
Detection engineering — OpenTide + DetectionOps
This skill governs how detection content moves through its lifecycle. It pairs OpenTide's object lineage (Threat Vector → Detection Objective → Detection Rule) with the practical mechanics of converting validated hunting queries into production-grade detection rules on the platforms CoreTide deploys to.
Always pair with: language skills (
kusto-query-language,splunk-spl-processing), platform skills (microsoft-sentinel,microsoft-defender-endpoint,crowdstrike-falcon,carbon-black-cloud,sentinelone-singularity,harfanglab), and the OpenTide object skills (opentide-threat-vector,opentide-detection-objective,opentide-detection-rule).
1. OpenTide sequencing
- Evidence / threat modelling —
opentide-threat-vector(TVM YAML, Phase A intel structuring + Phase B authoring). - Detection intent & signals —
opentide-detection-objective(DOM YAML, signals, data contracts, methodology). - Deployable artefacts —
opentide-detection-rule(MDR YAML, plus platform-specificconfigurations.*blocks).
Default rule: one object type per change request unless explicitly running an end-to-end vertical slice (drill, pilot deployment, framework-bootstrap).
CoreTide-aligned configuration keys most commonly seen: