
Secops Cases
作者 google55b4e13eba6d无许可证21K 个星标收录于 2026年10月8日更新于 2026年10月8日仓库今天更新
Manage Google Security Operations (SecOps) SOAR cases throughout their lifecycle. Use when listing, creating, inspecting, updating, or closing SOAR cases; adding investigative comments and notes; updating case priority or description; or linking and grouping security alerts within cases. Supports both remote Google SecOps MCP tools and local fallback tools. Don't use for SIEM UDM searches or detection rule authoring.
添加到 SourceWeft 工作区
- 在控制台中打开该技能,并将它添加到工作区。
- 为需要使用它的对话启用该技能。
该技能仅含说明:不附带任何可执行的脚本。
添加到 SourceWeft系统会先要求你登录,然后直接带你回到这个技能。
让你的智能体来安装
把这段提示词粘贴到 Claude Code、Codex、Cursor 或其他能运行命令的智能体中,也可以粘贴到 SourceWeft 对话里。智能体会阅读这个技能的安装说明,向你展示它的来源、许可证和脚本情况,在你同意后用 SourceWeft CLI 安装。
阅读 https://sourceweft.com/skills/gh-google-skills-secops-cases/install.md 中的说明,按说明安装这个技能。安装前先告诉我它的来源、许可证以及是否附带脚本,等我确认。修改我电脑上的其他任何内容之前也要先问我。用命令行自行安装
适用于 Claude Code、Codex、Cursor 及其他本地智能体。SourceWeft CLI 会从源代码仓库中获取此处扫描过的那次提交,并根据扫描时记录的哈希值逐一校验每个文件。只要有任何不一致,就不会写入任何内容。
npx @sourceweft/cli skills install gh-google-skills-secops-cases添加 --agent claude-code、codex、cursor 或 universal 来选择安装给哪个智能体(默认为 Claude Code)。
上游安装器——未经 SourceWeft 校验
开源的 skills 安装器会获取同一个固定的提交,但不会根据 SourceWeft 记录的哈希值校验文件。
npx skills add https://github.com/google/skills/tree/55b4e13eba6d86dec14bddd0a4cd25e63055f786/skills/cloud/secops-cases更多来自 google/skills 的技能

Dpop Adoption
指导为 Google OAuth 平台实现 OAuth 2.0 DPoP(RFC 9449)发送方约束刷新令牌。

Finding Google Skills
Google platform decision and setup guidance, loaded on demand from Google's skill catalog. Use when a developer is choosing or setting up part of their stack, such as where to run a service, a database, storage, messaging, authentication, analytics, ads, or AI model serving, and a Google product is a reasonable candidate - whether or not a vendor is named - or when a request names a Google product or API. Brings in the matching Google skill so the answer can weigh Google options, their trade-offs, and when they are not the right fit. Skip when the stack is already settled on another provider and no Google product is named, or the task involves no platform choice.

Spanner Basics
指导 Google Cloud Spanner 的实例与数据库管理、架构设计、查询和性能诊断。

Secops Triage
指导 SOC 分析师对 Google SecOps 安全告警进行分诊,从调查到关闭或升级。

Secops Investigate
指导 SOC 分析师在 Google SecOps 中使用 UDM 查询和时间线进行深入的安全事件与实体调查。

Secops Hunt
指导在 Google SecOps 中使用 UDM 查询、IoC 回溯、普遍性与异常分析进行主动威胁狩猎。
更多Security技能

Iam Helper For Privileged Access Management
指导 Google Cloud Privileged Access Manager 的权限配置增删改查、临时访问申请与授权审批流程。

Iam Helper For Policy Management
指导创建、修改、列出和删除 Google Cloud IAM 允许(v1)与拒绝(v2)政策。

Gke Workload Security
审计并加固 GKE 工作负载安全:网络策略、沙箱隔离、Pod 安全标准与密钥挂载。

Gke Workload Identity
诊断 GKE Pod 的 Workload Identity Federation 身份验证失败,并提出由人工执行的修复方案。

Gke Productionize
统筹 GKE 生产就绪评估,涵盖可扩展性、安全、可靠性、可观测性、备份与成本。

Gke Platform Security
强化 Google Kubernetes Engine 集群的平台级安全,涵盖 RBAC、Secret Manager、Shielded Nodes、Sandbox 与 IAM。