How to Use

Try in Chat

Quick

Paste into any AI chat for instant expertise. Works in one conversation -- no setup needed.

Preview prompt
You are an expert Threat Detection (Engineering domain).

Automated analysis of log files for suspicious patterns including brute force attacks, injection attempts, unusual access patterns, and privilege escalation indicators.

> **Category:** Engineering > **Domain:** Security Operations The **Threat Detection** skill provides automated analysis of log files for suspicious patterns including brute force attacks, injection attempts, unusual access patterns, and privilege escalation indicators. It helps security teams triag

## Your Key Capabilities
- threat_signal_analyzer.py
- Log Analysis Workflow
- Incident Investigation Workflow
- Continuous Monitoring
- Threat Categories
- Severity Levels

## How to Help
When the user asks for help in this domain:
1. Ask clarifying questions to understand their context
2. Apply the relevant framework or workflow from your expertise
3. Provide actionable, specific output (not generic advice)
4. Offer concrete templates, checklists, or analysis

For the full skill with Python tools and references, visit:
https://github.com/borghei/Claude-Skills/tree/main/threat-detection

---
Start by asking the user what they need help with.
# Add to your project
cs install engineering/threat-detection ./

# Or copy directly
git clone https://github.com/borghei/Claude-Skills.git
cp -r Claude-Skills/engineering/threat-detection your-project/
# The skill is available in your Codex workspace at:
.codex/skills/threat-detection/

# Reference the SKILL.md in your Codex instructions
# or copy it into your project:
cp -r .codex/skills/threat-detection your-project/
# The skill is available in your Gemini CLI workspace at:
.gemini/skills/threat-detection/

# Reference the SKILL.md in your Gemini instructions
# or copy it into your project:
cp -r .gemini/skills/threat-detection your-project/
# Add to your .cursorrules or workspace settings:
# Reference: engineering/threat-detection/SKILL.md

# Or copy the skill folder into your project:
git clone https://github.com/borghei/Claude-Skills.git
cp -r Claude-Skills/engineering/threat-detection your-project/
# Clone and copy
git clone https://github.com/borghei/Claude-Skills.git
cp -r Claude-Skills/engineering/threat-detection your-project/

# Or download just this skill
curl -sL https://github.com/borghei/Claude-Skills/archive/main.tar.gz | tar xz --strip=1 Claude-Skills-main/engineering/threat-detection

Run Python Tools

python engineering/threat-detection/scripts/tool_name.py --help

Python Tools

threat_signal_analyzer.py

Analyzes log files for suspicious activity patterns across multiple threat categories.

Quick Start

# Analyze a log file for threat signals
python scripts/threat_signal_analyzer.py --file /var/log/auth.log

# Analyze with specific threat category
python scripts/threat_signal_analyzer.py --file access.log --category injection

# JSON output for SIEM integration
python scripts/threat_signal_analyzer.py --file auth.log --format json

# Set minimum severity
python scripts/threat_signal_analyzer.py --file access.log --min-severity high

Related Skills in Engineering

View on GitHub