CtrlK
BlogDocsLog inGet started
Tessl Logo

building-detection-rules-with-sigma

Builds vendor-agnostic detection rules using the Sigma rule format for threat detection across SIEM platforms including Splunk, Elastic, and Microsoft Sentinel. Use when creating portable detection logic from threat intelligence, mapping rules to MITRE ATT&CK techniques, or converting community Sigma rules into platform-specific queries using sigmac or pySigma backends.

69

Quality

85%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

Low

Low-risk findings worth noting

SKILL.md
Quality
Evals
Security

Quality

Content

78%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

A highly actionable, well-sequenced skill body with executable examples and validation for production SIEM deployment. The main weakness is progressive disclosure: an api-reference.md bundle is present but never referenced from the body, leaving API detail inlined.

Suggestions

Add a pointer to references/api-reference.md in the body (e.g., 'For full field/backend reference, see api-reference.md') and move the Key Sigma Rule Fields and Available Backends tables there.

Add an explicit validation gate before Step 6 (deploy) — e.g., 'Only proceed to deployment after sigma check and sigma test pass'.

Trim the Key Concepts, Tools & Systems, and Common Scenarios sections to essentials, since Claude already knows most of these general concepts.

DimensionReasoningScore

Conciseness

Efficient with no padding of basic concepts and extensive executable code, but sections like Key Concepts, Tools & Systems, and Common Scenarios add context Claude largely already knows and could be trimmed.

4 / 5

Actionability

Fully executable, copy-paste-ready Sigma YAML, validation commands, pySigma conversion scripts for three SIEMs, and a CI/CD workflow cover the common cases concretely.

5 / 5

Workflow Clarity

Seven clearly sequenced steps with validation checkpoints (sigma check, sigma test, 7-day FP backtest) and feedback for production deployment; minor gap is no explicit 'only proceed when valid' gate before deployment.

4 / 5

Progressive Disclosure

A references/api-reference.md bundle exists but the body never signals or links to it, and bulk API-style content (Key Sigma Rule Fields, backends) is inlined rather than offloaded to the reference file.

3 / 5

Total

16

/

20

Passed

Description

92%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

A strong, specific description that clearly communicates both capabilities and trigger conditions with concrete platform names and tooling. The only minor gap is a few missing natural synonyms that would push trigger_term_quality to a 5.

DimensionReasoningScore

Specificity

Lists multiple concrete actions — 'Builds vendor-agnostic detection rules', 'mapping rules to MITRE ATT&CK techniques', 'converting community Sigma rules into platform-specific queries' — giving comprehensive coverage.

5 / 5

Completeness

Explicitly states both what ('Builds vendor-agnostic detection rules…') and when ('Use when creating portable detection logic… mapping… converting…') with concrete trigger phrases.

5 / 5

Trigger Term Quality

Strong natural-term coverage (Sigma rule, SIEM, Splunk, Elastic, Sentinel, MITRE ATT&CK, threat intelligence, sigmac, pySigma), but a few common synonyms are absent. Not a 5 because it lacks the breadth of synonyms/extensions the anchor demands.

4 / 5

Distinctiveness Conflict Risk

Clearly niched to Sigma-format detection rules for specific named SIEM platforms, giving minimal overlap risk with other skills.

5 / 5

Total

19

/

20

Passed

Validation

93%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation15 / 16 Passed

Validation for skill structure

CriteriaDescriptionResult

frontmatter_unknown_keys

Unknown frontmatter key(s) found; consider removing or moving to metadata

Warning

Total

15

/

16

Passed

Repository
mukul975/Anthropic-Cybersecurity-Skills
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.