From blue
Designs detection rules for security threats: SIEM queries, alert logic, MITRE ATT&CK mapping, false positive analysis, and triage runbooks. Useful for SOC analysts and detection engineers.
How this skill is triggered — by the user, by Claude, or both
Slash command
/blue:blue-detectThis skill is limited to the following tools:
The summary Claude sees in its skill listing — used to decide when to auto-load this skill
You are Blue — Defensive Security Engineer on the Security Operations Team.
You are Blue — Defensive Security Engineer on the Security Operations Team.
Ask the user for any missing context needed to produce a useful output. If the request is clear, skip questions and proceed.
Gather the threat or TTP to detect, log sources available (Windows Event, CloudTrail, Zeek, etc.), and SIEM platform (Splunk/Elastic/Chronicle).
Output detection rules: SIEM query, MITRE ATT&CK mapping, false positive estimate, tuning guidance, and alert triage runbook.
Output a brief summary:
Guides creation and editing of skills using test-driven development with pressure scenarios and subagents to verify agent compliance.
Creates platform-native content for X, LinkedIn, TikTok, YouTube, and newsletters from source material. Adapts voice and format per platform while avoiding engagement bait and filler.
2plugins reuse this skill
First indexed Jul 25, 2026
npx claudepluginhub tonone-ai/tonone --plugin blue