Skip to content

opentidehq/opentide-detection-skills

v1.0.0EUPL-1.2

Detection engineering skills for OpenTide — TVM, DOM, and MDR authoring, hunt-to-rule workflows, MITRE ATT&CK, platform query languages, and defensive internals — with the OpenTide MCP server.

linux-internals

Linux operating system internals for detection engineering — process model (fork/exec, /proc filesystem, namespaces), user/group/capability model, auditd subsystem and rule authoring, eBPF hook points and security tools (Falco, Tetragon), systemd service model, PAM authentication, SSH key management, common persistence locations, container isolation boundaries (namespaces, cgroups, seccomp), and the mapping between Linux operations and detection telemetry. Use when authoring detections targeting Linux endpoints, servers, or container workloads.

Read SKILL.md at the source

Pinned to revision 591443442d56, so it is the text this page describes rather than whatever the author pushed since.

Files

Every link opens the file at its source, pinned to the revision this page describes.