Detection Engineering Coverage Evaluation

Automates the end-to-end detection engineering workflow in Google SecOps using MCP tools. Use when fetching threat intelligence from blogs, generating Threat Detection Opportunities (TDOs), simulating attacker behavior with synthetic UDM events, evaluating rule coverage, and generating new YARA-L 2.0 rules to close coverage gaps. Don't use when asked to perform threat hunting actions, and SOC investigative actions.

h3y6e e3f4d9f 5.2 KB Updated

File contents

h3y6e/agent-skills/tree/main/.vendor/skills/detection_engineering_coverage_evaluation commit e3f4d9ff29

Frequently asked questions

npx skillmds@latest add h3y6e/detection-engineering-coverage-evaluation