Secops Hunt

Expert guidance for proactive threat hunting in Google SecOps. Use when proactively hunting for threats, retroactively analyzing indicators of compromise (IoCs), performing prevalence searches across enterprise events, hunting for MITRE ATT&CK techniques, or detecting behavioral and statistical outliers using UDM queries. Don't use for incoming alert triage (use secops-triage), active incident response and timeline deep-dives on a known breach (use secops-investigate), or detection rule authoring (use secops-detection-engineering).

Google Updated 14.4k repo stars

File contents

google/skills/tree/main/skills/cloud/secops-hunt commit 709934e2a5

Frequently asked questions

npx skillmds@latest add google/secops-hunt