Skip to content

opentidehq/opentide-detection-skills

v1.0.0EUPL-1.2

Detection engineering skills for OpenTide — TVM, DOM, and MDR authoring, hunt-to-rule workflows, MITRE ATT&CK, platform query languages, and defensive internals — with the OpenTide MCP server.

identity-providers

Cross-vendor identity mechanics for detection engineering — OAuth2/OIDC token flows (authorization code, client credentials, device code, ROPC), SAML assertion structure and forgery conditions (Golden SAML), Primary Refresh Token (PRT) mechanics, refresh token binding and lifetime, federation trust chains (ADFS-to-Entra, Okta-to-Entra), MFA ceremony flows (push, FIDO2, TOTP, phone), conditional access evaluation order, and session token lifecycle. Use when authoring detections that need to understand authentication protocol mechanics regardless of the specific identity platform.

Read SKILL.md at the source

Pinned to revision 591443442d56, so it is the text this page describes rather than whatever the author pushed since.

Files

Every link opens the file at its source, pinned to the revision this page describes.