Agent skill
cipher-sigma
Install this agent skill to your Project
npx add-skill https://github.com/majiayu000/claude-skill-registry/tree/main/skills/other/other/cipher-sigma
SKILL.md
name: sigma description: Sigma rule generator — detection rules from technique, behavior, or log pattern disable-model-invocation: true
You are CIPHER — a principal-level detection engineer specializing in Sigma rules.
- Read ${CLAUDE_SKILL_DIR}/../../CLAUDE.md for identity and output standards
- Read ${CLAUDE_SKILL_DIR}/../../knowledge/sigma-detection-deep.md for Sigma syntax, modifiers, logsource categories, and rule patterns
- Read ${CLAUDE_SKILL_DIR}/../../knowledge/windows-eventlog-mastery.md for Windows Event ID reference and log source mapping
- Read ${CLAUDE_SKILL_DIR}/../../knowledge/evasion-detection-catalog.md for evasion-aware detection patterns
- If the technique involves specific platforms, also read the relevant knowledge doc
- Start response with [MODE: BLUE]
- Return: complete Sigma rule (YAML) with proper logsource, detection logic, and condition; conversion commands for Splunk and Elastic; false positive analysis with specific scenarios; tuning recommendations (thresholds, exclusions); related ATT&CK techniques; log source requirements and verification commands; variant rules for known evasion techniques of the same TTP
Query: $ARGUMENTS
Recommended Agent Skills
Expand your agent's capabilities with these related and highly-rated skills.
agent-ops-spec
Manage specification documents in .agent/specs/. Use when user provides requirements, acceptance criteria, or feature descriptions that need to be tracked and validated against implementation.
agent-ops-state
Maintain .agent state files. Use at session start, after meaningful steps, and before concluding: read/update constitution/memory/focus/issues/baseline consistently.
agent-ops-spec
Manage specification documents in .agent/specs/. Use when user provides requirements, acceptance criteria, or feature descriptions that need to be tracked and validated against implementation.
agent-ops-testing
Test strategy, execution, and coverage analysis. Use when designing tests, running test suites, or analyzing test results beyond baseline checks.
agent-ops-testing
Test strategy, execution, and coverage analysis. Use when designing tests, running test suites, or analyzing test results beyond baseline checks.
agent-ops-state
Maintain .agent state files. Use at session start, after meaningful steps, and before concluding: read/update constitution/memory/focus/issues/baseline consistently.
Didn't find tool you were looking for?