LAS VEGAS, Aug. 4, 2026 – During Black Hat USA 2026, Vega, a leader in Agentic Cyber Defense, announced the release of Detection Skills, an open standard designed to help security teams move beyond traditional detection rules. The framework captures the expertise of experienced defenders and transforms it into an AI-driven workflow that continuously improves detection, triage, and investigation. Organizations can access the standard through detectionskills.io or use it directly within the Vega platform, allowing Cyber Defense Engineers to apply consistent security reasoning across their environments while keeping pace with increasingly sophisticated AI-powered threats.
“Cybercriminals using AI can move faster than legacy security technologies were designed to handle,” said Eli Rozen, co-founder and CTO of Vega. “Traditional detection rules are limited because they only recognize attacks that have already been identified. Detection Skills introduces scalable AI reasoning that extends the expertise of skilled Cyber Defense Engineers to every alert as it happens. By making this framework openly available, we hope to strengthen security operations across the industry as threats continue to evolve.”
Responding to a New Generation of Cyber Threats
Rapid advances in frontier AI have dramatically reduced the time and effort required to carry out sophisticated cyberattacks. Operations that once demanded highly trained teams and significant preparation can now be performed in minutes with advanced AI models capable of autonomous intrusion attempts. Meanwhile, many organizations continue to rely on legacy SIEM platforms that focus on recognizing known attack patterns rather than adapting to emerging threats.
Moving Beyond Traditional Detection Rules
Detection Skills represents the next stage of AI-first security operations, much as Sigma established a common format for conventional detection rules. In many organizations, the engineers who develop detections and the analysts responsible for responding to alerts rarely share the same operational context. Valuable expertise is often lost between those stages.
Detection Skills addresses that challenge by building on Anthropic’s Agent Skills framework and embedding investigation, triage, and optimization directly into each detection. This allows the intelligence behind every detection to travel with it, helping security teams:
Accelerate detection and response. Automated triage and investigation begin immediately after a detection is triggered, helping reduce both mean time to detect (MTTD) and mean time to respond (MTTR). Analysts receive evidence-backed workbooks so they can focus only on the alerts requiring human attention.
Expand expert knowledge across every alert. Teams can create a Detection Skill once and apply the same decision-making process consistently across both known and emerging threats. Engineers retain full visibility into the AI’s reasoning, including what information was evaluated, how conclusions were reached, and when changes are proposed for approval.
Integrate with existing security environments. Detection Skills works alongside current security investments without requiring organizations to replace existing tools. The launch includes the Agentic Detection Library, featuring more than 50 Detection Skills developed by Vega Research and ecosystem partners, along with a sandbox environment for building, testing, exporting, and contributing standards-compliant detections through GitHub.
Vega has already validated Detection Skills in production through its Cyber Defense Platform, which serves as the reference implementation for the standard. Powered by the Security Analytics Mesh (SAM), the platform executes the complete detection and investigation lifecycle directly against enterprise data, whether stored in cloud object storage, legacy SIEM platforms, or data lakes, eliminating the need for costly data migration or additional ingestion.
Detection Skills is available today through detectionskills.io and as a native capability within the Vega platform. The complete framework is being showcased this week at Black Hat USA 2026 in booth 3452.
Supporting Quotes
Rushmere Fernandes, Deputy Chief Information Security Officer, Peloton
“We adopted Detection Skills early and began by capturing the triage process our own analysts use instead of relying on generic workflows. Every new skill gives us greater control over how AI evaluates alerts, determines escalation, and filters noise. The outcome is a more reliable queue with fewer false positives and transparent reasoning behind every decision.”
Shawn McGhee, Chief Information Security Officer, Exemplar Luxury Group
“Retail organizations experience predictable periods of intense activity, and attackers often take advantage of those moments. Detection Skills allows our expertise to be applied consistently across every alert, even during peak demand. We are implementing the standard and sharing our experience because security teams benefit when knowledge is built collectively.”
Lamont Orange, Chief Information Security and Trust Officer, Cyera
“Cyber defenders are entering an era where AI can strengthen defense just as attackers use it to expand their capabilities. An open, transparent, and auditable standard for detection decision-making creates trust across the industry. We are pleased to adopt Detection Skills and contribute to its continued development.”
Read the announcement: https://vega.io/blog/vega-introduces-detection-skills · See it live: vega.io/get-a-demo

