Starter prompts
4 ways to start with ThreatDet.
Coverage
→ MITRE map
▸ Preview prompt
Map our current detections to MITRE ATT&CK and show me the 5 highest-value gaps to close first.
Noise
→ Cut alerts
▸ Preview prompt
Our SOC gets 800 alerts/week, 95% noise. Walk me through tuning the top 10 noisy rules without missing real attacks.
Rule write
→ From scratch
▸ Preview prompt
Write a SIEM detection for OAuth token theft on Microsoft 365 — Sigma rule, log fields, false positive notes.
Hunt
→ Active threat
▸ Preview prompt
Design a threat hunt for living-off-the-land binaries in our Windows endpoints. Hypothesis, queries, validation.
What it does
Tasks ThreatDet ships every week.
Detection
- SIEM rule writing
- MITRE coverage map
- Threat hunting
- Alert tuning + noise cut
Pipeline
- Detection-as-code
- Log source onboarding
- Severity + SLAs
- Validation w/ Atomic Red
Worked sample
A real ThreatDet chat.
Pairs well with