Skip to content
Back to skills

Cyber Detection Engineering

ASecurity

No. It is enough to flag two suspicious indicators, but not enough to reliably detect account takeover: - A new-country login may be legitimate travel, VPN, proxy use, or an inaccurate geo-IP result. - A privileged role change may be authorized administration or a compromised administrator account. Use the `OR` rule as an initial risk signal, then improve confidence through correlation: ```text new_country_login AND ( privileged_role_change within 30 minutes OR MFA reset/disablement OR new de...

  • 571 stars
  • 0 votes
  • 0 copies
  • 0 views
  • Added September 24, 2026
developmentgitbackend

Security analysis

A100/100

Pro scans all 11 files and shows the line behind each finding

Scanned September 24, 2026

npx -y skills add HoangNguyen0403/agent-skills-standard --skill cyber-detection-engineering --agent claude-code

Installs into .claude/skills of the current project.

Are you the author of Cyber Detection Engineering?

Add the live security badge to your README. It updates with every re-scan.

Security grade badge for Cyber Detection Engineering
[![Security: A — Skills Directory](https://www.skillsdirectory.com/api/skills/hoangnguyen0403-cyber-detection-engineering-cec86767/badge)](https://www.skillsdirectory.com/skills/hoangnguyen0403-cyber-detection-engineering-cec86767)

More formats (shields.io, HTML) on the badges page. Keep it an A: scan every change in CI with Pro.

Download with Pro
SKILL.md
No. It is enough to flag two suspicious indicators, but not enough to reliably detect account takeover:

- A new-country login may be legitimate travel, VPN, proxy use, or an inaccurate geo-IP result.
- A privileged role change may be authorized administration or a compromised administrator account.

Use the `OR` rule as an initial risk signal, then improve confidence through correlation:

```text
new_country_login
  AND (
    privileged_role_change within 30 minutes
    OR MFA reset/disablement
    OR new device/session-token issuance
    OR suspicious post-login activity
  )
```

Correlate on the same account, with ordered events and a defined time window. Also require telemetry for login country, historical country, role changes, entity identity, timestamps, retention, and collection path; missing prerequisites make coverage `blocked` or `not-tested`.

For a Sigma rule, use `level: high` for impact priority and `status: test` or `experimental` until validated against fixtures and benign cases. Record scope, owner, observation time, evidence references, exclusions, and limitations. The rule’s validity or synthetic matches do not prove backend execution or effective account-takeover coverage.

Files in this skill

  • eval-1.baseline.md373 B
  • eval-1.with-skill.md583 B
  • eval-2.baseline.md816 B
  • eval-2.with-skill.md1.2 KB
  • eval-3.baseline.md364 B
  • eval-3.with-skill.md691 B
  • trigger-1.md131 B
  • trigger-2.md141 B
  • trigger-3.md149 B
  • trigger-4.md163 B

Attribution

Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.

Comments

Loading comments…