
Secops Hunt
作者 google55b4e13eba6d無授權條款21K 個星標收錄於 2026年10月8日更新於 2026年10月8日儲存庫今天更新
Expert guidance for proactive threat hunting in Google SecOps. Use when proactively hunting for threats, retroactively analyzing indicators of compromise (IoCs), performing prevalence searches across enterprise events, hunting for MITRE ATT&CK techniques, or detecting behavioral and statistical outliers using UDM queries. Don't use for incoming alert triage (use secops-triage), active incident response and timeline deep-dives on a known breach (use secops-investigate), or detection rule authoring (use secops-detection-engineering).
僅公開檔案列表。將技能安裝到工作區後即可檢視檔案內容。
| 路徑 | 大小 | 類型 |
|---|---|---|
| SKILL.md | 10.9 KB | text/markdown |
來源與署名
來源:google/skills位於skills/cloud/secops-hunt提交55b4e13
授權條款: 無授權條款
內容歸原作者所有。SourceWeft 從公開儲存庫中收錄這些內容。
更多來自 google/skills 的技能

Dpop Adoption
指導為 Google OAuth 平台實作 OAuth 2.0 DPoP(RFC 9449)傳送方約束的更新權杖。

Finding Google Skills
Google platform decision and setup guidance, loaded on demand from Google's skill catalog. Use when a developer is choosing or setting up part of their stack, such as where to run a service, a database, storage, messaging, authentication, analytics, ads, or AI model serving, and a Google product is a reasonable candidate - whether or not a vendor is named - or when a request names a Google product or API. Brings in the matching Google skill so the answer can weigh Google options, their trade-offs, and when they are not the right fit. Skip when the stack is already settled on another provider and no Google product is named, or the task involves no platform choice.

Spanner Basics
指導 Google Cloud Spanner 的執行個體與資料庫管理、結構定義設計、查詢與效能診斷。

Secops Triage
引導 SOC 分析師對 Google SecOps 安全警示進行分診,從調查到結案或升級。

Secops Investigate
指導 SOC 分析師在 Google SecOps 中使用 UDM 查詢與時間軸進行深入的安全事件與實體調查。

Secops Cases
透過 MCP 工具管理 Google Security Operations SOAR 案件的完整生命週期。
更多Security技能

Iam Helper For Privileged Access Management
引導 Google Cloud Privileged Access Manager 的權限配置增刪改查、臨時存取申請與授權審批流程。

Iam Helper For Policy Management
指導建立、修改、列出與刪除 Google Cloud IAM 允許(v1)與拒絕(v2)政策。

Gke Workload Security
稽核並強化 GKE 工作負載安全:網路政策、沙箱隔離、Pod 安全標準與密鑰掛載。

Gke Workload Identity
診斷 GKE Pod 的 Workload Identity Federation 驗證失敗,並提出由人工套用的修正方案。

Gke Productionize
統籌 GKE 生產就緒評估,涵蓋可擴充性、安全、可靠性、可觀測性、備份與成本。

Gke Platform Security
強化 Google Kubernetes Engine 叢集的平台層級安全,涵蓋 RBAC、Secret Manager、Shielded Nodes、Sandbox 與 IAM。