siem-rules

Installation
SKILL.md

SIEM Detection Rule Development

Framework: MITRE ATT&CK v16 Role: SOC Analyst, Security Engineer Time: 20-40 min per rule Output: Production-ready KQL or SPL detection query, correlation rule logic, tuning parameters


1. When to Use

If a target is provided via arguments, focus the review on: $ARGUMENTS

Invoke this skill when any of the following conditions are met:

Installs
11
GitHub Stars
19
First Seen
May 4, 2026
siem-rules — unitoneai/securityskills