Edge Copy setup link
Skill evidence / secops-investigate
Skill profile

secops-investigate

Expert guidance for deep security incident and entity investigations in Google SecOps.

What this skill does for you

Expert guidance for deep security incident and entity investigations in Google SecOps. Use when investigating cases, analyzing entities (hosts, IPs, domains, hashes, users), extracting and searching UDM events, performing asset and user timeline analysis, and detecting lateral movement across enterprise networks. Don't use for detection rule authoring or YARA-L tuning (use secops-detection-engineering), proactive hypothesis-driven hunting (use secops-hunt), initial alert triage (use secops-triage), or basic case status updates (use secops-cases).

Quoted from the skill description in the pinned source

Who made it

Publishergoogle
Repositoryskills
Installs507as of Sep 27, 2026

Use it with Edge

Set up Edge for me: read getedge.cc/SKILL.md and follow it. Then use Edge to load the secops-investigate skill from google/skills.

Paste it into Claude, ChatGPT, Codex or Cursor.

Or read the skill source first.

Security evidence

Security state at 2026-09-30: reviewed. State definitions. This records static evidence for this revision; live load eligibility is checked again.

3 static scans, 0 counted findings. The listed scanners recorded the results shown for this package revision.

ScannerDateResultFindings
Edge static checks2026-09-27Pass0
Cisco skill-scanner2026-09-27Pass0
Semgrep Edge rules2026-09-27Pass0

Static scans check the code, not how well the skill works.

Scanner scope, raw findings and mirrored provider records

Edge static checks (Edge-run): edge-static/1.0.1. Scope: Static patterns for remote execution, credentials with network sends, obfuscation, prompt overrides, hidden Unicode, binaries and persistence. Revision: f566651a2f60aecbc4654f8868fb239f85a783f6. Raw findings: . Counted findings: .

Cisco skill-scanner (Edge-run): cisco-skill-scanner/2.1.0. Scope: Local static, YARA, pipeline and behavioral analyzers; no LLM or AI Defense analysis. Revision: f566651a2f60aecbc4654f8868fb239f85a783f6. Raw findings: 1. Counted findings: .

Semgrep Edge rules (Edge-run): semgrep/1.178.0+edge-rules.c15016a36fd3+offline-v1. Scope: Six Edge-authored static rules with Semgrep CE; offline execution and metrics disabled. Semgrep-maintained rules excluded. Revision: f566651a2f60aecbc4654f8868fb239f85a783f6. Raw findings: . Counted findings: .

Source and licence

Repository
https://github.com/google/skills
Pinned skill file
View source at revision
Revision
f566651a2f60aecbc4654f8868fb239f85a783f6
Package hash
sha256:3623e9a6a0cff6e9d5115f9a5395131077b4ed823acf2535306b303f398142ec
Licence
Apache-2.0