pytm
81Build pytm Threat Models as Code
Threat modeling often becomes outdated and disconnected from architecture changes. This skill helps create pytm models, STRIDE analysis, and diagram workflows for security reviews and CI.
Build Portable Sigma Detection Rules
SIEM-specific rules are difficult to reuse and maintain across platforms. This skill structures Sigma detections, conversions, ATT&CK mappings, and compliance coverage.
Stop for confirmation before installing.
Review the plan and obtain explicit user consent before changing files.
Copy this request to your Agent. It includes the canonical Skill page and manifest.
Review the Skillstore skill "detection-sigma" from https://skillstore.io/skills/agentsecops-detection-sigma.md and its manifest at https://skillstore.io/api/skills/agentsecops-detection-sigma/manifest. Verify the artifact. Stop and obtain explicit user consent before installing or changing files.Your Agent should still show its plan and request any confirmation required by the security policy.
Use these links when an AI agent, crawler, or script needs clean context instead of reading the full page.
Using "detection-sigma". Create a Windows detection for encoded PowerShell commands.
Expected outcome:
A rule outline identifies process-creation logs, PowerShell image matching, encoded-command indicators, expected administrative false positives, medium severity, and ATT&CK T1059.001.
Using "detection-sigma". Tune a noisy failed-login rule.
Expected outcome:
The review recommends grouping failures by account and source, setting a time window, excluding approved scanners, and testing lockout and service-account behavior.
Using "detection-sigma". Map audit monitoring to NIST 800-53.
Expected outcome:
The coverage plan connects audit controls to authentication, process, account-management, and policy-change logs, then lists missing sources and required validation evidence.
Most static findings are false positives from defensive selectors, ATT&CK labels, citations, Markdown fences, and SIEM query examples. One network finding is confirmed because the deployment example performs an authenticated request. Separate findings cover disabled TLS verification, administrator placeholders, and unpinned dependencies.
These are real local capabilities that may be expected for this skill, so they require review but are not counted as confirmed malicious behavior.
Share the versioned assessment report, neutral badge, embed card, and citations. Skillstore reports evidence without deciding whether this Skill is safe.
https://skillstore.io/skills/agentsecops-detection-sigma/audits/10?utm_source=security_passport&utm_medium=share&utm_campaign=versioned_report[](https://skillstore.io/skills/agentsecops-detection-sigma?utm_source=security_passport_badge)<a href="https://skillstore.io/skills/agentsecops-detection-sigma?utm_source=security_passport_badge"><img src="https://skillstore.io/badges/skills/agentsecops-detection-sigma/security.svg" alt="Skillstore security assessment" loading="lazy"></a><iframe src="https://skillstore.io/embed/skills/agentsecops-detection-sigma.html" title="Skillstore Security Assessment" sandbox="allow-popups allow-popups-to-escape-sandbox" loading="lazy" referrerpolicy="no-referrer" width="420" height="180"></iframe>AgentSecOps. (2026). detection-sigma security audit report (audit version 10) [Author version 0.1.0]. Skillstore. https://skillstore.io/skills/agentsecops-detection-sigma/audits/10@techreport{agentsecops-agentsecops-detection-sigma-2026,
author = {AgentSecOps},
title = {detection-sigma security audit report (audit version 10)},
institution = {Skillstore},
year = {2026},
number = {10},
url = {https://skillstore.io/skills/agentsecops-detection-sigma/audits/10},
note = {Author version 0.1.0}
}cff-version: 1.2.0
message: "If you use this Skill, cite its author and this versioned security audit report."
title: "detection-sigma security audit report (audit version 10)"
version: "0.1.0"
type: report
authors:
- name: "AgentSecOps"
date-released: "2026-07-23"
url: "https://skillstore.io/skills/agentsecops-detection-sigma/audits/10"
identifiers:
- type: other
value: "skillstore:agentsecops-detection-sigma:audit:10"
description: "Skillstore immutable audit report identifier"
Create structured Sigma rules from observed behaviors, required log sources, and known false positives.
Compare backend query forms and identify field mappings or unsupported features before migration.
Connect monitoring controls to log sources, Sigma tags, rules, and documented coverage gaps.
Create a Sigma rule for [behavior] using [log source]. Include metadata, detection logic, false positives, severity, and ATT&CK tags.
Review this Sigma rule for syntax, field modifiers, condition logic, and false positives. Suggest targeted corrections and test cases: [rule].
Translate this Sigma rule concept for [SIEM]. Explain field mappings, unsupported features, and manual adjustments. Do not assume access to deployment credentials.
Design a coverage plan for [framework or threat set]. Map controls or techniques to log sources, Sigma rules, gaps, and validation evidence.
Author
AgentSecOpsLicense
MIT
Author version
v0.1.0
Skillstore revision
r2
Repository
https://github.com/AgentSecOps/SecOpsAgentKit/tree/main/skills/incident-response/detection-sigmaRef
9e952417e76879bc9d853e1b8b2cd6d6d8d4a1c2
Maintenance freshness
7/24/2026
Usage
8 downloads · 579 views
Build pytm Threat Models as Code
Threat modeling often becomes outdated and disconnected from architecture changes. This skill helps create pytm models, STRIDE analysis, and diagram workflows for security reviews and CI.
Secure Dockerfiles with Hadolint
Dockerfile mistakes can create insecure and unreliable container images. This skill provides Hadolint workflows, rule guidance, remediation examples, and reusable CI configurations.
Run Authorized Nuclei Security Scans
Known vulnerabilities and misconfigurations can escape manual review. This skill guides authorized Nuclei scans, template selection, validation, and reporting.
Audit Code with Semgrep
Security flaws can remain hidden across large, multilingual repositories. This skill guides focused Semgrep scans, triage, custom rules, CI gates, and standards-aligned remediation.
Scan Dependencies and Containers with Trivy
Security teams need consistent visibility into vulnerable components, images, and infrastructure configuration. This skill provides practical Trivy workflows for assessment, reporting, and remediation.
Automate OWASP ZAP DAST Scans
Security teams need repeatable runtime testing before releases. This skill guides authorized OWASP ZAP scans, authentication setup, API testing, and CI reporting.
Plan Authorized Red Team Exercises
by sickn33
Security teams need a clear structure for adversary simulation and reporting. This skill organizes MITRE ATT&CK concepts into planning, detection review, and report guidance.
Audit Software Releases with Evidence
by glenskii
Release decisions often rely on incomplete evidence and inconsistent standards. This skill applies structured controls, deterministic scoring, and mandatory gates to assess readiness.
Audit Python Web Apps Before Release
by glenskii
Python teams need repeatable checks for common application security controls. This skill provides configurable pytest coverage with clear evidence, boundaries, and release decisions.
Build an ISO 27001 Information Security Program
by davila7
HealthTech and MedTech teams need structured security governance that aligns operational risks with ISO 27001 requirements. This skill guides ISMS design, risk assessment, control selection, compliance monitoring, and certification preparation.
Manage Medical Device Risk Files
by alirezarezvani
Medical device teams need consistent risk management evidence across design, regulatory, and post-market work. This skill guides ISO 14971 planning, analysis, controls, and file maintenance.
Audit ISO 27001 ISMS Controls
by alirezarezvani
ISMS audits require clear scope, evidence, and risk-based priorities. This skill guides ISO 27001 audit planning, control testing, and readiness work.