⚡AgentSkills
🛡️ Cyber Defense & SOC · Detection & Purple Team

Validate detections with purple-team exercises

Safe technique emulation proving alerts fire end-to-end, producing concrete coverage evidence.

intermediate~40 minSOC AnalystsDetection EngineersThreat Hunters

Steps

  1. 1Select atomic tests matching your mapped priority techniques
  2. 2Run in isolated lab mirroring production logging config exactly
  3. 3Trace: did endpoint event reach SIEM parse correctly AND alert fire?
  4. 4Record three states: detected / ingested-not-alerted / not-ingested
  5. 5File engineering tickets per gap with retest dates
  6. 6Report coverage trend to leadership in techniques-validated terms

Common Pitfalls

  • ▲Testing in labs whose log pipelines differ from production
  • ▲Emulations risky enough to trigger real incidents uncontrolled

Commands

Install with skills CLI
$ npx skills add aniruddhaadak80/skills --skill detection-purple-purple-validation
Install globally
$ npx skills add aniruddhaadak80/skills --skill detection-purple-purple-validation -g

Tags

#purple-team#validation#atomic#cyber-defense-ops#detection-purple

Related skills

Ship detection rules like code: versioned, tested, tuned, and retired deliberately.

🛡️ Cyber Defense & SOC·~40m

Ship detection rules like code: versioned, tested, tuned, and retired deliberately.

🛡️ Cyber Defense & SOC·~40m

Scenario injects probing decision boundaries, revealing plan gaps without blame theater.

🛡️ Cyber Defense & SOC·~40m