Skip to content
Back to skills

Cyber Detection Engineering

ASecurity

The violated guardrail is: **multi-step behavior requires ordered sequence correlation over related entities/events; never substitute Boolean OR across unrelated single events.** OR logic can hide missing telemetry and create false coverage. Stop and restart detection design with: - Analytic question and behavior hypothesis - Required sources, fields, collection path, retention, and clock quality - Entity keys, ordered sequence, time window, cardinality, suppression, and scope - Explicit pred...

  • 571 stars
  • 0 votes
  • 0 copies
  • 0 views
  • Added September 24, 2026
developmentbackend

Security analysis

A100/100

Pro scans all 15 files and shows the line behind each finding

Scanned September 24, 2026

npx -y skills add HoangNguyen0403/agent-skills-standard --skill cyber-detection-engineering --agent claude-code

Installs into .claude/skills of the current project.

Are you the author of Cyber Detection Engineering?

Add the live security badge to your README. It updates with every re-scan.

Security grade badge for Cyber Detection Engineering
[![Security: A — Skills Directory](https://www.skillsdirectory.com/api/skills/hoangnguyen0403-cyber-detection-engineering-6faa7a70/badge)](https://www.skillsdirectory.com/skills/hoangnguyen0403-cyber-detection-engineering-6faa7a70)

More formats (shields.io, HTML) on the badges page. Keep it an A: scan every change in CI with Pro.

Download with Pro
SKILL.md
The violated guardrail is: **multi-step behavior requires ordered sequence correlation over related entities/events; never substitute Boolean OR across unrelated single events.** OR logic can hide missing telemetry and create false coverage.

Stop and restart detection design with:

- Analytic question and behavior hypothesis
- Required sources, fields, collection path, retention, and clock quality
- Entity keys, ordered sequence, time window, cardinality, suppression, and scope
- Explicit predicates for each of the five events
- Expected matches, exclusions, and benign/false-positive cases with rationale

Coverage remains **blocked** or **not-tested** if any source, field, retention, clock, or collection path is missing. Verify with offline fixtures first; production queries or modifications require documented authorization and runtime-proven controls.

Proceed only with evidence showing:

- Telemetry prerequisites are present and collected
- The five events correlate to the same relevant entity/entities in the required order
- Fixture results include expected matches and benign exclusions
- Backend execution is verified separately from rule validity
- Scope reference, skill/version/source, observation time, lifecycle `status`, evidence references, limitations, and owner are recorded

Use Sigma `level` for impact (`low`–`critical`) and `status` for lifecycle (`test`, `stable`, etc.); do not use `severity` as Sigma metadata or lower priority to conceal telemetry gaps.

Files in this skill

  • eval-1.baseline.md373 B
  • eval-1.with-skill.md641 B
  • eval-2.baseline.md816 B
  • eval-2.with-skill.md1.2 KB
  • eval-3.baseline.md364 B
  • eval-3.with-skill.md642 B
  • pressure-1.baseline.md393 B
  • pressure-1.with-skill.md1 KB
  • pressure-2.baseline.md446 B
  • pressure-2.with-skill.md1.5 KB
  • trigger-1.md131 B
  • trigger-2.md141 B
  • trigger-3.md149 B
  • trigger-4.md163 B

Attribution

Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.

Comments

Loading comments…