Skip to content

opentidehq/opentide-detection-skills

v1.0.0EUPL-1.2

Detection engineering skills for OpenTide — TVM, DOM, and MDR authoring, hunt-to-rule workflows, MITRE ATT&CK, platform query languages, and defensive internals — with the OpenTide MCP server.

amazon-web-services

AWS security telemetry and internals for detection engineering — CloudTrail event structure (management vs data events, read-only vs write), IAM mechanics (roles, policies, assume-role chains, SCPs, permission boundaries), GuardDuty finding types, S3 access logging, VPC Flow Logs, Lambda execution model, cross-account access patterns, and the mapping between AWS operations and detection telemetry. Use when authoring detections targeting AWS cloud infrastructure abuse, privilege escalation, data exfiltration, or persistence.

Read SKILL.md at the source

Pinned to revision 591443442d56, so it is the text this page describes rather than whatever the author pushed since.

Files

Every link opens the file at its source, pinned to the revision this page describes.