⚡AgentSkills
🛡️ Cyber Defense & SOC · Detection & Purple Team

Engineer detections through a full lifecycle (Microsoft Sentinel)

Ship detection rules like code: versioned, tested, tuned, and retired deliberately.

advanced~40 minSOC AnalystsDetection EngineersThreat Hunters

Steps

  1. 1Draft rule from hunt/intel with explicit logic rationale documented
  2. 2Backtest against 30 days of data; measure raw hit volume
  3. 3Tune out benign-true noise using environment baselines, not blanket exclusions
  4. 4Stage: silent-run in prod for one week comparing predicted vs actual hits
  5. 5Enable with severity matched to expected fidelity; document false-positive budget
  6. 6Review rule precision quarterly; retire or rewrite below threshold
  7. 7Deploy analytics rules as code via ARM/Bicep pipelines
  8. 8Watch ingestion latency when setting query frequency

Common Pitfalls

  • ▲Rules enabled then never revisited until they page falsely
  • ▲Exclusions so broad they hollow out the logic

Commands

Install with skills CLI
$ npx skills add aniruddhaadak80/skills --skill detection-purple-detection-rule-lifecycle-sentinel
Install globally
$ npx skills add aniruddhaadak80/skills --skill detection-purple-detection-rule-lifecycle-sentinel -g

Tags

#detection-engineering#as-code#cyber-defense-ops#detection-purple

Related skills

Ship detection rules like code: versioned, tested, tuned, and retired deliberately.

🛡️ Cyber Defense & SOC·~40m

Safe technique emulation proving alerts fire end-to-end, producing concrete coverage evidence.

🛡️ Cyber Defense & SOC·~40m

Scenario injects probing decision boundaries, revealing plan gaps without blame theater.

🛡️ Cyber Defense & SOC·~40m