Skip to content
Development
Skill

/author-detection-content

Turn validated security behavior into tested detection content. Use for Sigma, osquery, YARA-X, endpoint or SIEM queries, cloud detections, correlation, alert enrichment, and fixtures with explicit telemetry and false-positive controls.

From plugin
socket
7200 skills5 MCP
Install
$ npx -y skills add gaelic-ghost/socket --skill author-detection-content --agent claude-code

How it fires

How this skill gets triggered: by you, by Claude, or both.

  • Fires itselfAuto-invocation. Claude auto-loads it when your prompt matches the work.Auto-invocation is when the right skill fires by itself at the right moment, driven by a FLOW.md router and a hook, instead of you invoking it by name. It is the difference between a skill being installed and a skill actually getting used.Read the full definition →
  • You can call itInvoke it directly when you want it.
  • Slash command/author-detection-content

Context preview

The summary Claude sees to decide when to auto-load this skill.

Turn validated security behavior into tested detection content. Use for Sigma, osquery, YARA-X, endpoint or SIEM queries, cloud detections, correlation, alert enrichment, and fixtures with explicit telemetry and false-positive controls.

SKILL.md

author-detection-content.SKILL.md
name: author-detection-content
description: Turn validated security behavior into tested detection content. Use for Sigma, osquery, YARA-X, endpoint or SIEM queries, cloud detections, correlation, alert enrichment, and fixtures with explicit telemetry and false-positive controls.

Author Detection Content

Overview

Detect the validated behavior at the most reliable telemetry layer. Use `author-yara-x-rules` for artifact pattern rules; use this workflow for event, query, correlation, and alert content.

Read [references/detection-quality.md](references/detection-quality.md) before choosing logic or deployment severity.

Workflow

1. Define objective and response.

  • State the behavior, threat/finding source, protected surface, expected alert consumer, urgency, and action.

2. Identify telemetry prerequisites.

  • Record source/product/version, event types/fields, collection permissions, normalization, retention, latency, and known blind spots.

3. Select durable features.

  • Prefer behavior and context combinations over mutable infrastructure or one noisy field.
  • Map to ATT&CK only when evidence supports it.

4. Author content.

  • Include title/ID, description, status, author/date, references, log source, logic/query, fields, false positives, level/severity, tags, and test notes as the target format permits.

5. Test fixtures.

  • Include validated positive events, benign negatives and near-misses, missing/renamed fields, ordering/time-window cases, duplicate events, volume/performance, and known platform variants.

6. Tune and validate response.

  • Improve logic before adding exclusions; verify enrichment and runbook lead an analyst to decisive evidence.

7. Deploy and maintain.

  • Record target environments, owner, version, rollout, alert volume, suppression/exception expiry, health checks, and review triggers.

Output

Return detection content, telemetry contract, evidence provenance, fixture results, false positives/limits, performance, severity/response, deployment plan, and owner/review date.

Read more
Ships withsocket

Stuff for Agents on macOS Promo audio: Socket Codex Marketplace Promo

Get the whole plugin

Other skills on socket.