Detection Engineering Coverage Evaluation

Automates the end-to-end detection engineering workflow in Google SecOps using MCP tools. Use when fetching threat intelligence from blogs, generating Threat Detection Opportunities (TDOs), simulating attacker behavior with synthetic UDM events, evaluating rule coverage, generating new YARA-L 2.0 rules to close coverage gaps, and with user approval, deploy them to SecOps. Don't use when asked to perform threat hunting actions, and SOC investigative actions.

Harlieunadjusted52 7c02c27 7.7 KB Updated

File contents

Harlieunadjusted52/skills/tree/main/skills/cloud/detection-engineering-coverage-evaluation commit 7c02c27a54

Frequently asked questions

npx skillmds@latest add harlieunadjusted52/detection-engineering-coverage-evaluation