Skip to content
Back to skills

Author Detection Content

ASecurity

Turn validated security behavior into tested detection content. Use for Sigma, osquery, YARA-X, endpoint or SIEM queries, cloud detections, correlation, alert enrichment, and fixtures with explicit telemetry and false-positive controls.

  • 7 stars
  • 0 votes
  • 0 copies
  • 2 views
  • Added September 5, 2026
ai-agentssecurityperformance

Security analysis

A100/100

Pro scans all 3 files and shows the line behind each finding

Scanned September 5, 2026

npx -y skills add gaelic-ghost/socket --skill author-detection-content --agent claude-code

Installs into .claude/skills of the current project.

Are you the author of Author Detection Content?

Add the live security badge to your README. It updates with every re-scan.

Security grade badge for Author Detection Content
[![Security: A — Skills Directory](https://www.skillsdirectory.com/api/skills/gaelic-ghost-author-detection-content/badge)](https://www.skillsdirectory.com/skills/gaelic-ghost-author-detection-content)

More formats (shields.io, HTML) on the badges page. Keep it an A: scan every change in CI with Pro.

Download with Pro
SKILL.md
---
name: author-detection-content
description: Turn validated security behavior into tested detection content. Use for Sigma, osquery, YARA-X, endpoint or SIEM queries, cloud detections, correlation, alert enrichment, and fixtures with explicit telemetry and false-positive controls.
---

# Author Detection Content

## Overview

Detect the validated behavior at the most reliable telemetry layer. Use `author-yara-x-rules` for artifact pattern rules; use this workflow for event, query, correlation, and alert content.

Read [references/detection-quality.md](references/detection-quality.md) before choosing logic or deployment severity.

## Workflow

1. Define objective and response.
   - State the behavior, threat/finding source, protected surface, expected alert consumer, urgency, and action.
2. Identify telemetry prerequisites.
   - Record source/product/version, event types/fields, collection permissions, normalization, retention, latency, and known blind spots.
3. Select durable features.
   - Prefer behavior and context combinations over mutable infrastructure or one noisy field.
   - Map to ATT&CK only when evidence supports it.
4. Author content.
   - Include title/ID, description, status, author/date, references, log source, logic/query, fields, false positives, level/severity, tags, and test notes as the target format permits.
5. Test fixtures.
   - Include validated positive events, benign negatives and near-misses, missing/renamed fields, ordering/time-window cases, duplicate events, volume/performance, and known platform variants.
6. Tune and validate response.
   - Improve logic before adding exclusions; verify enrichment and runbook lead an analyst to decisive evidence.
7. Deploy and maintain.
   - Record target environments, owner, version, rollout, alert volume, suppression/exception expiry, health checks, and review triggers.

## Output

Return detection content, telemetry contract, evidence provenance, fixture results, false positives/limits, performance, severity/response, deployment plan, and owner/review date.

Files in this skill

  • SKILL.md2 KB
  • agents/openai.yaml247 B
  • references/detection-quality.md896 B

Attribution

Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.

Comments

Loading comments…