.fyi
SkillsMCPPluginsSubagents

Browse by category

DevOps & CI/CD SkillsProductivity & Workflow SkillsOther SkillsProduct & Project Management SkillsDocumentation & Knowledge SkillsCode Review & Refactor SkillsBackend & APIs SkillsAgent Meta & Communication SkillsResearch SkillsSecurity SkillsUX UI & Design SkillsTesting & QA SkillsSee all →

Every Claude Code skill, MCP server, plugin and subagent in one directory. Searchable, comparable, and one command from installed. Live stats from GitHub, npm and PyPI.

We're on Product HuntYour agent's app storeCheck it out →
Agent SkillsMCP ServersPluginsSubagentsCoding Agents
CollectionsOfficial publishersGlossaryFAQBlogSearchSavedFeedback
PrivacyTermsllms.txtSitemap

made with ♥ · © 2026 aaaa.fyi

Independent project · real data from public registries

…/mhaggis/security-detections-mcp
home/skills/mhaggis/security-detections-mcp
mhaggis avatar

mhaggis/security-detections-mcp

15 skills

View on GitHub
$npx skills add mhaggis/security-detections-mcp
SkillInstalls
analytic-story-builderCreate grouped detection narratives that tie individual rules into coherent threat stories.—atomic-red-team-testingExecute and validate adversary emulation tests using Atomic Red Team.—attack-navigator-generatorGenerate MITRE ATT&CK Navigator layers for coverage visualization, threat actor mapping, and gap analysis.—attack-range-builderBuild and manage adversary emulation lab environments for any SIEM.—coverage-analysisAnalyzes detection coverage using Sigma, Splunk, and Elastic rules.—cti-detection-engineerExpert CTI analyst specializing in detection engineering, MITRE ATT&CK mapping, behavioral analysis, and intelligence-driven detection creation.—custom-atomics-deploymentCreate, deploy, and execute custom Atomic Red Team tests (T9999.XXX series) for detection validation.—data-source-mapperMap MITRE ATT&CK techniques to required data sources across Windows, Linux, cloud, network, and EDR telemetry.—detection-reviewerExpert detection quality assurance reviewer. Validates detection rules before deployment with comprehensive checks on structure, logic, MITRE mappings, false…—detection-test-engineerExpert at creating test scenarios for detections using Atomic Red Team, attack simulation tools, and validation frameworks.—detection-yaml-engineerExpert at creating and validating detection rule files for multiple SIEM platforms.—pr-extension-workflowAnalyze pull requests for detection coverage gaps and recommend additional detections, story alignments, and test coverage to extend PRs before merge.—spl-optimizerOptimize detection queries for performance across Splunk (SPL), Microsoft Sentinel (KQL), and Elastic Security (EQL/ES|QL).—supply-chain-analystAnalyze software supply chain attacks across package registries (npm, PyPI, RubyGems), CI/CD pipelines (GitHub Actions, GitLab CI), and container ecosystems.—threat-report-parserExpert at analyzing unstructured threat intelligence reports (CISA alerts, vendor blogs, research papers) and extracting actionable detection logic, TTPs,…—