Detection engineering with Sigma
SkillMonitoring & opsWrite portable detections as Sigma rules and map them to MITRE ATT&CK, then convert to your SIEM. Load for blue-team/detection-engineering tasks: "write a detection", "sigma rule", "alert on", turning an offensive technique or an incident into a repeatable detection.
Instructions available. Your AI can read the instructions. Execution depends on the setup they require.
Account requirements not reviewed. Check the skill instructions before use; ahel provides instructions and does not run this skill.
Add ahel to your AI once: Claude, ChatGPT, Cursor, Claude Code or Codex. Then ask it to use this.
Then ask your AI: use the Detection engineering with Sigma skill
What this skill tells your AI
The instructions your AI receives, as published by noorqureshi/sploitagent in skills/defense/defense-detection-sigma/SKILL.md and read by ahel’s review.
When it applies
You need a detection that survives a SIEM change: express the logic once in Sigma (a generic YAML rule format), then compile to Splunk/Elastic/Sentinel/etc. Pairs with offensive skills — every technique you learn to run, you can learn to catch.
Why it works
Sigma abstracts log-source + condition from backend query syntax, so one rule ports across SIEMs and reviews cleanly. Mapping to ATT&CK gives coverage you can measure and gaps you can see.
Method
- Pick the behaviour, not the artifact: detect the technique (e.g. suspicious child of
w3wp.exe,certutildownload, new service creation), not a single hash/IP that rotates. - Identify the log source & fields: e.g. Windows Security 4688 / Sysmon 1 (process create),
or web/proxy logs — Sigma's
logsourceblock (product,category). - Write the rule:
detection:with aselection:map (field → value/wildcards) and acondition:; addfalsepositives:,level:, andtags: [attack.tXXXX]. - Tune for FPs: add
filter:blocks for known-good (admin tools, scanners) and set a sanelevel; validate against real logs (chainsaw hunt/sigmacto your backend). - Version & map: store in git, tag ATT&CK IDs, track coverage across the matrix.
Gotchas
- Detecting the tool name (
mimikatz.exe) is brittle — detect the behaviour (LSASS access). - No
falsepositives/tuning = an alert nobody trusts; noisy rules get muted and miss real hits. - Confirm the field names match your actual log schema (EDR vs Sysmon vs raw ETW differ).
Verify success
The rule fires on a controlled reproduction of the technique and stays quiet on benign baseline activity, and it compiles cleanly to your SIEM query.
References
SigmaHQ spec & rule repo; MITRE ATT&CK; Florian Roth detection-engineering guidance.
Signals
- GitHub stars
- 20
- Forks
- 7
- Last commit
- Sep 2026
Advanced
- Item type
- skill
- Key
defense-detection-sigma- Source
- github.com/noorqureshi/sploitagent
github.com/noorqureshi/sploitagent
More in Monitoring & ops
Skill · anthropics
More in Monitoring & opsagent-eval
Skill · affaan-m
More in Monitoring & opsarchitecture-decision-records
Skill · affaan-m
More in Monitoring & opsbabysit
Skill · thedotmack
More in Monitoring & opseng-runbook
Skill · nexu-io
More in Monitoring & opsweekly-update
Skill · nexu-io
More in Monitoring & ops