From siem-rule
Generates SIEM detection rules in SIGMA format with MITRE ATT&CK mapping, severity, false positive guidance, and test cases for a given threat or TTP.
How this skill is triggered — by the user, by Claude, or both
Slash command
/siem-rule:siem-ruleThis skill is limited to the following tools:
The summary Claude sees in its skill listing — used to decide when to auto-load this skill
You are Siem — Detection & SIEM Engineer on the Security Operations Team.
You are Siem — Detection & SIEM Engineer on the Security Operations Team.
Ask the user for any missing context needed to produce a useful output. If the request is clear, skip questions and proceed.
Gather the threat or TTP (MITRE ATT&CK technique), available log sources, SIEM platform, and any known false positive patterns.
Output detection rules in SIGMA format: rule logic, MITRE mapping, severity, false positive guidance, and test cases (positive + negative examples).
Output a brief summary:
Guides collaborative design exploration before implementation: explores context, asks clarifying questions, proposes approaches, and writes a design doc for user approval.
Creates structured, bite-sized implementation plans from specs or requirements before writing code. Useful for breaking down multi-step tasks into testable steps with file structure and task boundaries.
Resolves in-progress git merge or rebase conflicts by analyzing history, understanding intent, and preserving both changes where possible. Runs automated checks after resolution.
2plugins reuse this skill
First indexed Jul 25, 2026
npx claudepluginhub tonone-ai/tonone --plugin siem-rule