Turn validated security behavior into tested detection content. Use for Sigma, osquery, YARA-X, endpoint or SIEM queries, cloud detections, correlation, alert enrichment, and fixtures with explicit telemetry and false-positive controls.
Scanned 9/5/2026
Install to Claude Code
npx -y skills add gaelic-ghost/socket --skill author-detection-content --agent claude-codeInstalls into .claude/skills of the current project.
Are you the author of Author Detection Content?
Add the live security badge to your README — it updates automatically with every re-scan.
[](https://www.skillsdirectory.com/skills/gaelic-ghost-author-detection-content)More formats (shields.io, HTML) on the badges page.
---
name: author-detection-content
description: Turn validated security behavior into tested detection content. Use for Sigma, osquery, YARA-X, endpoint or SIEM queries, cloud detections, correlation, alert enrichment, and fixtures with explicit telemetry and false-positive controls.
---
# Author Detection Content
## Overview
Detect the validated behavior at the most reliable telemetry layer. Use `author-yara-x-rules` for artifact pattern rules; use this workflow for event, query, correlation, and alert content.
Read [references/detection-quality.md](references/detection-quality.md) before choosing logic or deployment severity.
## Workflow
1. Define objective and response.
- State the behavior, threat/finding source, protected surface, expected alert consumer, urgency, and action.
2. Identify telemetry prerequisites.
- Record source/product/version, event types/fields, collection permissions, normalization, retention, latency, and known blind spots.
3. Select durable features.
- Prefer behavior and context combinations over mutable infrastructure or one noisy field.
- Map to ATT&CK only when evidence supports it.
4. Author content.
- Include title/ID, description, status, author/date, references, log source, logic/query, fields, false positives, level/severity, tags, and test notes as the target format permits.
5. Test fixtures.
- Include validated positive events, benign negatives and near-misses, missing/renamed fields, ordering/time-window cases, duplicate events, volume/performance, and known platform variants.
6. Tune and validate response.
- Improve logic before adding exclusions; verify enrichment and runbook lead an analyst to decisive evidence.
7. Deploy and maintain.
- Record target environments, owner, version, rollout, alert volume, suppression/exception expiry, health checks, and review triggers.
## Output
Return detection content, telemetry contract, evidence provenance, fixture results, false positives/limits, performance, severity/response, deployment plan, and owner/review date.
Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.
No comments yet. Be the first to comment!