Security professionals can now search across six major detection rule platforms at once. This includes Sigma, Splunk, Elastic, KQL, Sublime, and CrowdStrike. You can find rules for specific attack techniques like process injection or credential dumping.
The tool maps every rule to the MITRE ATT&CK framework. It shows you which techniques your security stack covers and where the gaps are. You can even generate a visual map called an ATT&CK Navigator layer.
Whether you are a blue team member or a penetration tester, this skill helps you find detection gaps and build new rules. It works with over 8,200 detection rules and supports many threat actors and software.
Global
mkdir -p ~/.claude/skills/security-detections-mcpProject
mkdir -p .claude/skills/security-detections-mcpSource Repository
Azure Compliancemicrosoft/azure-skills
Audit Azure compliance and Key Vault expiration with azqr scans
Firebase Security Rules Auditorfirebase/agent-skills
Find weak spots in Firestore rules and get clear fixes
Golang Securitysamber/cc-skills-golang
Find and fix security flaws in Go code using expert guidance and automated tools
Clerk Nextjs Patternsclerk/skills
Secure your Next.js app with Clerk middleware, server actions, and caching
Persona It Admingoogleworkspace/cli
Keep your digital workspace safe with IT admin security workflows
Two Factor Authentication Best Practicesbetter-auth/skills
Secure user logins with two-factor authentication using Better Auth
Gws Modelarmor Create Templategoogleworkspace/cli
Create new templates for Google Model Armor to protect AI apps from harmful content
Gws Modelarmor Sanitize Promptgoogleworkspace/cli
Clean user prompts safely with Google Model Armor templates