detection-tuner

Investigate noisy/common alerts and create false positive (FP) rules to suppress benign detections. Analyzes detection frequency over 7 days, identifies patterns, generates and tests FP rules with operator approval before deployment. Use for tuning detection noise, reducing alert fatigue, suppressing known-safe activity, or when specific detections need filtering. Human-in-the-loop workflow ensures no FP rules are deployed without explicit approval.

$ Installer

git clone https://github.com/refractionPOINT/documentation /tmp/documentation && cp -r /tmp/documentation/marketplace/plugins/lc-essentials/skills/detection-tuner ~/.claude/skills/documentation

// tip: Run this command in your terminal to install the skill

Repository

refractionPOINT
refractionPOINT
Author
refractionPOINT/documentation/marketplace/plugins/lc-essentials/skills/detection-tuner
2
Stars
1
Forks
Updated4d ago
Added1w ago