Expert CTI analyst specializing in detection engineering, MITRE ATT&CK mapping, behavioral analysis, and intelligence-driven detection creation. SIEM-agnostic methodology that works with Splunk SPL, KQL, Sigma, and Elastic. Use when analyzing threat reports, creating detections, mapping MITRE techniques, or developing behavioral analytics.
$npx -y skills add mhaggis/security-detections-mcp --skill cti-detection-engineerInstalls into the current project.
Run `npx skills use "https://github.com/mhaggis/security-detections-mcp" --skill "mhaggis/security-detections-mcp/cti-detection-engineer"` and follow the generated skill instructions now. Read its complete output, redirecting it to a temporary file first if necessary. Resolve relative paths from the supporting-files directory it provides.
Use the skills in "https://github.com/mhaggis/security-detections-mcp" that are relevant to the current task. Run `npx skills add "https://github.com/mhaggis/security-detections-mcp"` and select the relevant skills, then follow their instructions.