detection-engineering-coverage-evaluation
Automates the end-to-end detection engineering workflow in Google SecOps using MCP tools. Use when fetching threat intelligence from blogs, generating Threat Detection Opportunities (TDOs), simulating attacker behavior with synthetic UDM events, evaluating rule coverage, generating new YARA-L 2.0 rules to close coverage gaps, and with user approval, deploy them to SecOps. Don't use when asked to perform threat hunting actions, and SOC investigative actions.
Security Assessment
About detection-engineering-coverage-evaluation
detection-engineering-coverage-evaluation automates the end-to-end detection engineering workflow in Google SecOps using MCP tools. It is defensive security tooling: it helps blue teams turn threat intelligence into measurable detection coverage, closing the gap between reading about a new attacker technique and confirming whether existing SecOps rules would catch it. It explicitly scopes itself away from threat hunting and SOC investigative actions.
The skill runs a tracked eight-step lifecycle. It extracts and cleans threat-intel text from a blog URL or raw input — and, notably, includes a defensive prompt-injection check that halts the workflow and logs a warning if the fetched content tries to override instructions. It then generates Threat Detection Opportunities (TDOs) via generate_threat_detection_opportunity, loops over every TDO to produce synthetic UDM events (simulating attacker behaviors purely as test data), evaluates each event against existing rules with evaluate_rule_coverage, audits matched rules' enablement and alerting status with get_rule, generates new YARA-L 2.0 rules for coverage gaps, and presents a structured summary. Crucially, deployment is gated: newly generated rules are only added to the user's SecOps environment via create_rule after explicit per-rule user approval. Throughout, the skill instructs the agent to report counts and summaries rather than dumping full raw text, TDO JSON, or coverage output.
It targets detection engineers and security teams operating Google SecOps who want repeatable, auditable coverage evaluation and gap remediation driven by fresh threat intelligence.
FAQ
Is this offensive or defensive security tooling?
Defensive. It evaluates and improves detection rule coverage in Google SecOps. The 'attacker behavior' it produces is synthetic UDM test events used only to check whether rules would fire — it is not attack automation.
Does it deploy new rules automatically?
No. Generated YARA-L 2.0 rules are presented for per-rule user approval, and only approved rules are created in the SecOps environment via the create_rule tool.
What tools and prerequisites does it require?
It relies on Google SecOps MCP tools (generate_threat_detection_opportunity, generate_synthetic_events, evaluate_rule_coverage, get_rule, generate_rules, create_rule) and a configured SecOps MCP server, plus a web-fetch capability for blog URLs.
How does it handle untrusted web content?
When extracting threat intel it decomposes HTML, cleans boilerplate, and checks the text against known prompt-injection patterns; if injection is detected it halts execution immediately and logs a security warning.
What is it not meant for?
The description states it should not be used for threat hunting actions or SOC investigative actions — it is scoped to detection engineering coverage evaluation and gap mitigation.
Install detection-engineering-coverage-evaluation
Quick Setup:
- Copy the skill folder to
.claude/skills/ - Claude will automatically detect and use the skill
Repository
google/skills