Skip to content
Blog

Vega Introduces Detection Skills: The New Open Standard for AI Reasoning in Agentic Cyber Defense

4 Aug 20266 min

Security is moving from matching static patterns to agentic loops that scale reasoning. 

The world changed when frontier AI learned to attack. LLMs can autonomously identify exposures, chain exploits, and break into an organization in minutes. And frontier capability gets distilled and open-sourced fast, so the attacker talent pool is now effectively unlimited.

Against that, most organizations are still relying on twenty-year-old technology designed to solve a problem that no longer exists. Static rules worked when threats could be known and codified as a pattern; today’s attacks are generated by AI, not repeated. Meanwhile AI is producing more “dark data” than at any point in history - too expensive to ingest, too voluminous to index - and the legacy SIEM’s answer is an invoice: pay more every year to see less of your own environment.

Underneath both problems sits an older one: detection was only ever half the workflow. The reasoning after the match is where defense is won or lost, and that judgment - triage, investigation, optimization - lived in analysts’ heads and left with every resignation. Attackers automated their entire kill chain. Defenders automated the match, and stopped there.

From Rules to Reasoning

Today, Vega is proud to introduce Detection Skills: an open standard, built on Anthropic’s Agent Skills format, for everything after the match. It’s already live at detectionskills.io. Triage, investigation, and tuning are written as scalable AI skills versioned that live inside the detection and run as one continuous agentic loop. 

The Cyber Defense Engineer's job used to end at the match. Now the same person architects the reasoning that follows. When a detection fires, triage skills handle the noise at machine speed, so only what matters escalates to an incident. Investigation skills analyze the incident before a human looks: what happened, which entities, and the evidence behind every conclusion. Optimization skills close the loop, writing approved verdicts back into the rule and turning investigated alerts into proposals for new coverage. Engineers approve every change: judgment stays with people, and the repetitive work is done before they arrive. The best reasoning on a security team used to cover one shift. Now it covers every alert, and each detection leaves the system sharper than it found it. It's detection engineering’s “Shift Left” moment: For the first time, the full craft of defense, not just the match, can be written down, versioned, and shared.

Why an open standard

Sigma standardized what a detection matches. YARA did it for malware, STIX and TAXII for threat intel. Nothing standardized what happens after the match, so the most valuable knowledge in security operations never traveled past the person who wrote it down.

An open standard changes that. When one team encodes its judgment as a skill, every team that runs it inherits it. Defenders’ experience can finally compound across organizations the way attackers’ tooling always has. The advantage attackers gained from AI is not permanent, but no single vendor takes it back. We believe this loop is the only way defenders get ahead and stay there - so everything ships open on day one, to every company. We proved the standard inside the Vega Cyber Defense Platform, ensuring it is ready for everyone to adopt.

Standards win when a community makes them inevitable. Sigma earned that. ATT&CK earned that. Detection Skills are built to earn it.

The industry is converging on the same conclusion. Nvidia and more than thirty other companies recently launched the Open Secure AI Alliance on the principle that AI-era defense must be built in the open, where every defender can inspect, adapt, and run it. Detection Skills brings that principle to the SOC.

Live today at detectionskills.io

What you need to put Detection Skills to work is open now:

  • The standard, versioned and open to the community.
  • The Detection Skills Library, starting with 50+ skills from Vega Research and our partners, the same skills running inside the Vega platform right now.
  • A sandbox to build a detection, attach a skill, preview the verdict, and export spec-compliant YAML, as well as a GitHub repository to contribute your own skills back to the community.

The outcomes are the ones security leaders have been promised for a decade: less noise, faster answers, coverage that grows. Triage runs before the alert exists, enabling noise prevention as opposed to just helping deal with the noise once it’s painful. A large digital commerce company on the Vega platform cut mean triage time from 1 hour to less than 2 minutes.

Cyber Defence Engineers are now able to instantly deploy expertise in emerging Threat Landscapes. With adoption of Agentic AI booming, the addition of relevant Detection Skills has enabled instant levelling up of Agentic Detection and Triage, tailored to a brand new use-case - dangerous model activity. 

Detection Skills also unlock another outcome - more efficient adoption of AI. Skills enable intelligent and more intentional Agentic reasoning. Detection Engineers maintain control of what and how AI will be utilized once the detection fires. This eliminates the need for a single, “catch-all” Agents that are both wasteful and inherently slower

Detection Skills in the Vega platform

Vega is the pioneer of Agentic Cyber Defense. The standard belongs to everyone, but runs deepest where it was born: the Vega platform, where skills reach the entire data estate in real time - no ingest budget deciding what they’re allowed to see. We built the reference implementation first, so anyone implementing the standard knows what it looks like done right. Here it is in practice:

Step 1: Build the detection. Compose it in a detection notebook - combine deterministic logic with Agentic Reasoning that will execute against the results once a match is found.

Step 2: Attach the skills. Select skills for triage, investigation, detection optimization, and more from the Skill Library, or build your own. 

Step 3: Approve the optimization. As the loop runs, tuning proposals arrive with their reasoning attached. Approve, adjust, or reject; approved verdicts write back into the rule, and the detection gets sharper with every fire.

The spec tells any team how to build this. The platform is where it’s already running.

An invitation

We want practitioners shaping v1 now, not evaluating it after it’s locked: people building detections at scale, eliminating maintenance debt, living in the gap between what fires and what gets investigated. Take the spec. Run a skill against your noisiest detection. Tell us where the format breaks against real data. Publish a skill and it’s in the library with your name on it.

Attackers already share their tooling. Cyber Defense Engineers should be able to design and collaborate on the reasoning layer they use to defend. We get ahead of AI-driven attacks together, or not at all.

The full framework launches this week at Black Hat USA 2026.

Book a demo · Explore the library · Read the specification

Detection Skillsdetection engineeringagentic detectionsoc transformation

Read more

All articles