googleSandy
- 3 skills
- 0 followers
- 8 hours ago last updated
- ▌ Secops Siem Search · googlesandy bundleUse when writing or running Google Security Operations (SecOps/Chronicle) SIEM queries or investigations — UDM filter queries, stats/aggregation, event-event joins, raw log search, reference list lookups, entity investigations (users, hosts, IPs, files, domains), enriched data queries (geolocation, VirusTotal), entity context search (graph.*), or understanding data availability timing. Use when a user asks to search, investigate, hunt, query, or find data in SecOps SIEM.
- ▌ Secops Detection Engineering · googlesandy bundleUse when creating, testing, deploying, or managing Google SecOps detection rules — the detection engineering workflow, retrohunts, rule quotas, detection delays, context-aware analytics (entity graph in rules), risk scoring, error troubleshooting, performance optimization, or composite detections. Complements secops-yara-l (YARA-L query syntax) with the detection engineering workflow. Triggers: "create a detection rule", "deploy rule", "retrohunt", "rule not firing", "detection delay", "entity graph in rule", "risk score rule", "composite detection", "rule error", "tune a rule".
- ▌ Secops Yara L · googlesandy bundleUse when writing YARA-L 2.0 detection rules or complex search queries for Google SecOps — single-event rules, multi-event correlation, sliding window detections, composite rules, outcome aggregations, conditional logic, multi-stage queries, or any YARA-L syntax questions. Triggers: "write a detection rule", "create a rule", "YARA-L rule for", "detect when", "alert when", "correlate events", "multi-stage query", "composite detection", "outcome section", "match over".