Skip to content

sodejm/detection-quality-workbench

v0.1.0PolyForm-Noncommercial-1.0.0

Evaluate detection rule quality, dependencies, schema drift, and regression baselines for Sentinel KQL and Splunk SPL.

What this package declares

The file a client reads when it loads this plugin, exactly as this revision carries it.

plugin.json
{
  "$schema": "https://agent-plugins.org/schemas/1.0.0/plugin.schema.json",
  "name": "detection-quality-workbench",
  "version": "0.1.0",
  "description": "Evaluate detection rule quality, dependencies, schema drift, and regression baselines for Sentinel KQL and Splunk SPL.",
  "author": {
    "name": "Justin Soderberg",
    "url": "https://github.com/sodejm"
  },
  "repository": "https://github.com/sodejm/copilot-operation-plugin-for-security",
  "license": "PolyForm-Noncommercial-1.0.0",
  "keywords": [
    "cybersecurity",
    "detection-engineering",
    "detection-quality",
    "kql",
    "microsoft-sentinel",
    "precision-recall",
    "regression-testing",
    "rule-validation",
    "splunk",
    "spl"
  ],
  "extensions": {
    "com.openai": {
      "displayName": "COPS Detection Quality & Regression Workbench",
      "category": "Developer Tools"
    },
    "org.cops": {}
  }
}

What else this package ships

These files come with the package and this site does not publish them. They are listed so you know what is there before you install it.

  • prerequisites.json
View on GitHub

Client extensions

Data this package carries for particular clients. The directory lists the clients named and never reads what is addressed to them.

  • com.openai
  • org.copsships a directory of files