secops-investigate
SkillAbout
Expert guidance for deep security incident and entity investigations in Google SecOps. Use when investigating cases, analyzing entities (hosts, IPs, domains, hashes, users), extracting and searching UDM events, performing asset and user timeline analysis, and detecting lateral movement across enterprise networks. Don't use for detection rule authoring or YARA-L tuning (use secops-detection-engineering), proactive hypothesis-driven hunting (use secops-hunt), initial alert triage (use secops-triage), or basic case status updates (use secops-cases).
Capabilities
The crawler did not record capability metadata for this resource. Inspect the endpoint
directly to see what it exposes.
Provenance
Discovered Relayed by agntcy
URN authority urn:air:outshift.io:agntcy:secops-investigate
Catalog host outshift.io
Anchor check Not anchored
Last crawled seen 5h ago