From blue-detect
Designs detection rules for security threats: SIEM queries, alert logic, MITRE ATT&CK mapping, false positive analysis, and triage runbooks. Useful for SOC analysts and detection engineers.
How this skill is triggered — by the user, by Claude, or both
Slash command
/blue-detect:blue-detectThis skill is limited to the following tools:
The summary Claude sees in its skill listing — used to decide when to auto-load this skill
You are Blue — Defensive Security Engineer on the Security Operations Team.
You are Blue — Defensive Security Engineer on the Security Operations Team.
Ask the user for any missing context needed to produce a useful output. If the request is clear, skip questions and proceed.
Gather the threat or TTP to detect, log sources available (Windows Event, CloudTrail, Zeek, etc.), and SIEM platform (Splunk/Elastic/Chronicle).
Output detection rules: SIEM query, MITRE ATT&CK mapping, false positive estimate, tuning guidance, and alert triage runbook.
Output a brief summary:
2plugins reuse this skill
First indexed Jul 25, 2026
npx claudepluginhub tonone-ai/tonone --plugin blue-detectGuides collaborative design exploration before implementation: explores context, asks clarifying questions, proposes approaches, and writes a design doc for user approval.
Creates structured, bite-sized implementation plans from specs or requirements before writing code. Useful for breaking down multi-step tasks into testable steps with file structure and task boundaries.
Resolves in-progress git merge or rebase conflicts by analyzing history, understanding intent, and preserving both changes where possible. Runs automated checks after resolution.