Engineer and audit SIEM detection rules — log source coverage, Sigma / KQL / SPL / Elastic query authoring, MITRE ATT&CK mapping, false-positive tuning, and detection-as-code workflows. Use when the user mentions 'SIEM,' 'detection engineering,' 'detection rules,' 'Sigma,' 'KQL,' 'SPL,' 'Splunk,' 'Sentinel,' 'Elastic,' 'Wazuh,' 'Chronicle,' 'detection-as-code,' 'MITRE ATT&CK mapping,' 'log coverage,' 'alert tuning,' 'use case development,' or needs help building or improving security detections.
$npx -y skills add briiirussell/cybersecurity-skills --skill siem-detectionInstalls into the current project.
Run `npx skills use "https://github.com/briiirussell/cybersecurity-skills" --skill "briiirussell/cybersecurity-skills/siem-detection"` and follow the generated skill instructions now. Read its complete output, redirecting it to a temporary file first if necessary. Resolve relative paths from the supporting-files directory it provides.
Use the skills in "https://github.com/briiirussell/cybersecurity-skills" that are relevant to the current task. Run `npx skills add "https://github.com/briiirussell/cybersecurity-skills"` and select the relevant skills, then follow their instructions.