Google · detection-engineering

Google Detection Engineering Agent

MCP-accessed assistant that evaluates coverage and drafts YARA-L rules.

First observed 2026-08-18 · Last verified 2026-08-27 ·FRESH · ASI-1.0 · ASI-TAXONOMY-1.1

Deterministic executive summary

EMERGINGASSISTIVEREAD-ONLY

Google Detection Engineering Agent has 1 confirmed capability assertion(s) and 1 confirmed control assertion(s). Evidence maturity is EMERGING; autonomy is ASSISTIVE; action authority is READ-ONLY. No qualifying independent validation is recorded.

What actually differs?

The documented boundary is READ-ONLY with ASSISTIVE operation. This describes authority and initiation, not effectiveness. No qualifying independent validation is recorded.

buyer

Treat missing independent validation as NONE_FOUND, not proof of ineffectiveness.

competitive

Compare documented action authority, trigger model, lifecycle, and evidence breadth; do not compare vendor outcome claims as equivalent measurements.

confidence

EMERGING under ASI-1.0; No qualifying independent validation is recorded.

governance

Control evidence covers 1 scoped control assertion(s); verify local policy configuration before enabling write actions.

operational

Plan operating procedures around ASSISTIVE initiation and READ-ONLY action authority.

technical

Current evidence establishes 1 scoped capability assertion(s); undocumented capabilities remain UNKNOWN.

Derived under ASI-1.0; last verified 2026-08-27.

Lifecycle

UNKNOWN · UNKNOWN

Evidence EV-GOOGLE-DEA-PUBLIC

public sources conflict on preview phase

Agents

detection

Detection Engineering Agent

Evaluates coverage and drafts YARA-L rules through MCP tools.

Capabilities: Detection authoring· Controls: A human must review and manually create rules produced by the Detection Engineering Agent.

Autonomy and control

Derived autonomy A0

Trigger
HUMAN_INITIATED · LOW · FRESH
Persistence
UNKNOWN · LOW · UNKNOWN
Permission scope
READ_ONLY · LOW · FRESH
Human gate
PRE_ACTION · LOW · FRESH

Each facet is separately evidence-backed; the A-label is derived.

A human must review and manually create rules produced by the Detection Engineering Agent.

AFFIRMED

Architecture

UNKNOWN — no architecture assertion is established.

Capabilities

Detection authoring

The Detection Engineering Agent drafts YARA-L rules but does not upload them automatically.

AFFIRMED

Capability evidence

Vendor documentation
HIGH
Public demonstration
NONE_FOUND
Independent validation
NONE_FOUND
Production effectiveness
UNKNOWN

ASI-1.0: Rows represent evidence categories; assertion support confidence is intentionally not rendered beside the capability name.

Assertion support

HIGH under ASI-1.0:Recomputed at publication semantic_as_of with current freshness and unresolved-contradiction state.

Evidence and provenance

VENDOR DOCUMENTATION EV-GOOGLE-DEA-DRAFT · E1

This tool does not automatically upload the rule into your Google SecOps system. In order to add any rule, review the text and then manually create new rules from the tool output.
Canonical source →

Evidence conflicts

No human-confirmed conflict is published for this system.

Recent changes

NO_MATERIAL_CHANGE is recorded for this profile.

Unknowns

Any evidence-panel row marked UNKNOWN is not a negative capability claim. Any NONE_FOUND row means the current governed corpus contains no qualifying evidence.

Sources

Compare claims with evidence categories