Skip to content

opentidehq/opentide-detection-skills

v1.0.0EUPL-1.2

Detection engineering skills for OpenTide — TVM, DOM, and MDR authoring, hunt-to-rule workflows, MITRE ATT&CK, platform query languages, and defensive internals — with the OpenTide MCP server.

google-cloud-platform

Google Cloud Platform security telemetry for detection engineering — Cloud Audit Logs structure (Admin Activity, Data Access, System Event, Policy Denied), IAM mechanics (roles, service accounts, workload identity federation, impersonation), GCP-specific attack patterns (service account key theft, cross-project access, storage exfiltration), VPC Flow Logs, and the mapping to Google SecOps (Chronicle) YARA-L and SIEM ingestion. Use when authoring detections targeting GCP infrastructure abuse.

Read SKILL.md at the source

Pinned to revision 591443442d56, so it is the text this page describes rather than whatever the author pushed since.

Files

Every link opens the file at its source, pinned to the revision this page describes.