Secops Detection Engineering

Use when creating, testing, deploying, or managing Google SecOps detection rules — the detection engineering workflow, retrohunts, rule quotas, detection delays, context-aware analytics (entity graph in rules), risk scoring, error troubleshooting, performance optimization, or composite detections. Complements secops-yara-l (YARA-L query syntax) with the detection engineering workflow. Triggers: "create a detection rule", "deploy rule", "retrohunt", "rule not firing", "detection delay", "entity graph in rule", "risk score rule", "composite detection", "rule error", "tune a rule".

googleSandy Updated

File contents

googleSandy/secops-skills/tree/main/skills/secops-detection-engineering commit 843b05036a

Frequently asked questions

npx skillmds@latest add googlesandy/secops-detection-engineering