Skip to content

opentidehq/opentide

v1.0.0EUPL-1.2

Detection skills for opentide repositories. Agents model threats, define what to detect, and write the rules and queries, with the platform and internals context each detection depends on.

windows-internals

Windows operating system internals relevant for detection engineering — process creation chain (CreateProcess to token assignment), access token and privilege model (SeDebugPrivilege, integrity levels, UAC), DLL loading order and hijacking surface, service control manager architecture, COM/DCOM/WMI execution model, named pipe IPC, ETW provider landscape, AMSI architecture, registry hive structure, and the mapping between OS-level operations and the telemetry they produce. Use when authoring detections that need to understand WHY a behaviour is suspicious at the OS level, not just WHAT tool produces it.

Read SKILL.md at the source

Pinned to revision 8a28d97335f1, so it is the text this page describes rather than whatever the author pushed since.

Files

Every link opens the file at its source, pinned to the revision this page describes.