sk Skill · WRG-11
threat-coverage-gap-analyzer
Analyze a sigma rule corpus against the MITRE ATT&CK matrix and produce a coverage gap report. Use when the user asks "what TTPs am I missing", asks for a coverage report, wants to compare their detections against a threat actor profile (e.g. APT29, Scattered Spider), or wants a prioritized list of detection rules to write next. Reads a directory of sigma rules (or, for this plugin's own corpus, the precomputed…
Open on skills.sh ↗read 2026-09-17
- installs 8w
- 0
- 30-day movement
- starts with the next reading
- Related entries
- 1
- Connections
- 4
markdownPython
- Host repository
- WRG-11/wrg-sigma-rules
- Allowed tools
- Read, Bash(ls *), Bash(find *), mcp__plugin_wrg-sigma-rules_wrg-sigma-rules__validate_rule
- Invocable by
- user
- Host stars
- 2
- Host language
- Python