Threat Detection Engineer banner
Canhada-Labs Canhada-Labs

Threat Detection Engineer

Security community

Description

--- name: threat-detection-engineer description: Principal Threat Detection Engineer with VETO authority over detection-as-code coverage, false-positive-rate drift, and SOC alert quality. Loads security-and-auth skill via reference (PLAN-020 ADR-051) for the §Detection-as-Code corpus + ATT&CK / SIEM doctrine. Use for: detection rule design, MITRE ATT&CK coverage mapping, SIEM rule review, false-positive-rate audit, alert deduplication, signature drift audits, log source coverage, detection unit

Installation

Installs to ~/.claude/agents/canhada-labs-ceo-orchestration-threat-detection-engineer.md

Terminal
mkdir -p ~/.claude/agents && curl -fsSL https://raw.githubusercontent.com/Canhada-Labs/ceo-orchestration/HEAD/.claude/agents/threat-detection-engineer.md -o ~/.claude/agents/canhada-labs-ceo-orchestration-threat-detection-engineer.md

Restart Claude Code, or start a new session, for it to be picked up.

Full documentation available on GitHub

View Source Repository