My Hacktoberfest 2026 Plan: An Open-Source Detection Skill (Not a PR Count)
Updated: 1 day ago
Hacktoberfest Changed This Year, and the Change is Exactly Why I'm In
For years, Hacktoberfest meant one thing: open four pull requests in October and earn a t-shirt. It got people into open source, but it also overwhelmed maintainers with low-effort, box-checking PRs. This year, MLH, DEV, and DigitalOcean rebuilt it. No more PR counting. Instead, it's about building with open-source and open-weight AI. You can write your first open-source skills.md, build an agent, fine-tune an open-weight model, or simply follow your curiosity.
That reframe turned Hacktoberfest from "a thing developers do" into "a thing that fits my lane." I'm not going to count PRs. I'm going to build one real, useful artifact — and I'm telling you now, in public, so I actually finish it.
What I'm Building: An Alert-to-ATT&CK Mapping Skill
I'm writing an open-source skills.md — a reusable, shareable instruction file — that does one specific job: take a security alert and map it to the MITRE ATT&CK framework.
If you've never worked a SOC shift, here's why that's the thing I picked. When an alert fires, a SOC analyst's real job isn't just "is this bad?" It's what technique this is, where it sits in the attacker's playbook, what they're likely to do next, and how I escalate it. MITRE ATT&CK is the shared language security teams use to answer that — a giant, structured map of how attackers actually behave. Mapping an alert to ATT&CK is the daily reasoning loop of the job.
So a skill that does that mapping cleanly isn't a toy. It's the exact muscle a Tier 1 analyst uses every shift, packaged so anyone can reuse it.
Why This One, and Not a Flashier Build
I could've gone for an agent or a Sigma detection rule. I chose the ATT&CK mapping skill on purpose. The reasoning is the same discipline I've been writing about all through my cert prep.
ATT&CK mapping is what SOC job descriptions actually ask for — triage and technique identification, not (yet) detection engineering. It's the entry-level reasoning, done well. It's also honest for a first-time open-source contributor: the ATT&CK framework is public and well-documented, so I can build something genuinely accurate without pretending to a depth I haven't earned. A Sigma rule that's subtly wrong undercuts you; a thoughtful ATT&CK mapping reads as competent even to a senior analyst.
A Sigma-rule skill makes a perfect next one — the sequel, once this lands. One step toward analyst, the next toward detection engineer. A roadmap, not a one-off.
Why It's the Whole Storm-to-SOC Thing in One File
Here's the part that made me smile when it clicked.
Mapping an alert to a technique is finding what doesn't belong and naming what it is. That’s the exact instinct I built chasing anomalies in atmospheric data — see the signal that's off, identify what it actually is, and place it in a pattern. I'm not learning a new reasoning skill for this. I'm translating one I already have into SOC vocabulary and freezing it into a file other people can use.
The tool changes. The question doesn't.
How I'll Prove It (and Where You'll See It)
No skill counts if it just lives on my laptop, so here's the accountability half:
It goes in a public repo — open source, reusable, MIT-ish, the whole point of Hacktoberfest.
I'll write up the build here on DataSec Chronicles — what the skill does, how I structured it, and what I learned making my first open-source contribution.
The finished skill is the recap. When it's done, I'll show you the actual file, not a description of one. Same deal I make with every number on this blog: I show the real thing.
That's the difference between a skill you can name and one you can show — and this month, I'm building the shown version.
The Importance of Community in Open Source
Open source isn't just about code. It's about community. When I think about my journey, I realize how much I've learned from others. The support and insights from fellow contributors have been invaluable.
Joining a community means sharing knowledge. It means asking questions and getting answers. It’s a space where everyone can grow together.
Tips for New Contributors
If you're new to open source, here are some tips to get started:
Start Small: Don’t feel pressured to tackle huge projects right away. Look for smaller issues to fix.
Read the Documentation: Familiarize yourself with the project's guidelines and coding standards.
Ask for Help: Don’t hesitate to reach out. Most communities are welcoming and eager to assist newcomers.
Stay Consistent: Regular contributions, even small ones, can lead to significant growth over time.
How I'd Explain This in a SOC Interview
Ask me what I did with open source this fall, and here's the answer: I built and published an open-source skill that maps security alerts to the MITRE ATT&CK framework — the same triage reasoning a Tier 1 analyst runs on every alert, packaged so it's reusable and public. I picked it deliberately over a flashier build because it's the reasoning the job actually needs, and because I could do it accurately rather than approximately. It's a small thing, honestly made, and it's real — you can read the file. That's the analyst mindset I'd bring to your console: identify the technique, place it in the attacker's playbook, and be honest about what the evidence supports.
October's the month. The framework is open, the plan is public, and the finished skill is coming. If you're doing Hacktoberfest too — you don't have to count PRs anymore. You can build one real thing that says who you're becoming.
Final Thoughts on Hacktoberfest
Hacktoberfest is more than just a month of coding. It’s a chance to connect, learn, and grow. This year, I’m excited to embrace the new direction. I’m ready to build something meaningful and share it with the community.
Let’s make this Hacktoberfest a memorable one!
Storm to SOC — read the map, then move. 💜



Comments