Secops Detection Engineering

Author, validate, test, and deploy YARA-L 2.0 detection rules and evaluate end-to-end detection coverage gaps in Google SecOps. Use when writing new detection rules, tuning existing rules, validating syntax, testing logic against historical telemetry, or evaluating detection coverage against threat intelligence blogs, CVE disclosures, and Threat Detection Opportunities (TDOs) using synthetic UDM events and long-running coverage analysis. Don't use for alert triage (use secops-triage), deep forensic event reconstruction on infected hosts (use secops-investigate), or case management operations (use secops-cases).

Google Updated 14.4k repo stars

File contents

google/skills/tree/main/skills/cloud/secops-detection-engineering commit 4a8d31959b

Frequently asked questions

npx skillmds@latest add google/secops-detection-engineering