blue-team-detection
This plugin provides detection engineering and threat hunting capabilities using Sigma and YARA rules, with agents and commands for building detection-as-code workflows and executing hypothesis-driven hunts mapped to MITRE ATT&CK techniques. It generates SIEM-specific translations (Splunk SPL, Elastic KQL, Microsoft Sentinel KQL) and supports structured threat hunting methodologies to catch adversary behavior across the kill chain.
Install
Source: https://github.com/HermeticOrmus/LibreSecOps-Claude-Code/tree/HEAD/plugins/blue-team-detection
What it's made of
2 commands · 2 agents · 2 skills
- Commands
- 2
- Agents
- 2
- Skills
- 2
- MCP servers
- 0
- Hooks
- 0
What it needs & plugs into
- API keys
- none
- Paid services
- none detected
- External tools
- none
- Talks to
- nothing external detected
Analyzed . Facts extracted from the plugin's files. Prose generated by claude-haiku-4-5-20251001.
Is this your plugin?
Claim it to keep the card accurate and enter the weekly contest. Requires signing in as the GitHub owner (HermeticOrmus).