Transforms static detection rules into a continuously improving agentic loop. Open to every Cyber Defender at detectionskills.io, natively integrated on Vega platform
— Vega, the pioneer of Agentic Cyber Defense, today launched Detection Skills: an open standard that redefines security operations for the AI era. The standard captures a team’s expert judgment as a self-improving agentic loop across detection, triage, and investigation.

Available to the community as an open standard, or natively within the best-in-class Vega platform, they allow modern Cyber Defense Engineers to architect their reasoning once and scale it across everything they defend. It gives every company an answer to the question that matters most: can our defense keep pace with AI?
“AI-driven adversaries bypass static rules in every legacy SIEM, and no rule catches an attack it has never seen,” said Eli Rozen, co-founder and CTO, Vega. “Detection Skills answer with scaled AI reasoning that brings the judgment of your best Cyber Defense Engineers to every alert, in real-time. We made the standard open to ensure the whole industry rises with it: as attacks scale, defense compounds.”
Why Now
Frontier AI has collapsed the economics of cyberattacks. Intrusions that took skilled teams weeks now take minutes, with advanced models breaking containment and autonomously breaching organizations. Defenses built on legacy SIEM have not kept pace: they can only recognize known patterns in a threat landscape where attacks are generated, not repeated.
From Static Rules to AI Reasoning
Just as Sigma defined the traditional detection rule format, Detection Skills is what comes next for AI-first Cyber Defense teams. The engineer who builds a detection and the analyst who answers it at 2 a.m. often never meet, and the context dies in the handoff.
Detection Skills solves that: built on the Agent Skills framework originally developed by Anthropic, it attaches triage, investigation, and optimization directly to the detection, so the reasoning travels with it, enabling security teams to:
- Detect and decide at AI speed. Triage and investigations run automatically the moment a detection fires, slashing MTTD and MTTR. Only what matters reaches a human, with a finished, evidence-backed workbook attached.
- Scale cyber defense expertise. Author a skill once and the same judgment reaches every alert, known or unknown. Engineers keep complete transparency and control over the AI’s reasoning: what it checked, why it decided, and no change without their sign-off.
- Adopt without disruption. Works alongside existing security investments. It launches with the Agentic Detection Library: 50+ skills from Vega Research and our partners, plus a sandbox to build, test, and export spec-compliant detections, and GitHub to contribute your own. .
Vega proved Detection Skills in production on its Cyber Defense Platform, the standard’s reference implementation. Built on the Security Analytics Mesh (SAM), the platform runs the full loop directly on an organization’s data wherever it lives, across cloud object storage, Legacy SIEMs, and data lakes, with no data migration or ingestion tax.
Everything is live today at detectionskills.io and within the Vega platform. The full framework debuts this week at Black Hat USA 2026 at booth 3452.
Rushmere Fernandes, Deputy Chief Information Security Officer, Peloton
“We adopted Detection Skills early and started by encoding our own triage logic, the way our team actually works an alert, not a generic playbook. Every skill we ship gives us more explicit control over what the AI checks, escalates, and dismisses. The result is a queue we trust: fewer false positives, and every verdict arrives with its reasoning attached.”
Shawn McGhee, Chief Information Security Officer, Exemplar Luxury Group
“Retail runs on peak moments, and attackers know exactly when those are. My team cannot be the constraint on a Saturday in December. Detection Skills gives us leverage we can plan around: the expertise is written down, it runs on every alert, and it holds up when volume spikes. We are adopting it and sharing what we learn, because no security team should have to rebuild this work alone.”
Lamont Orange, Chief Information Security and Trust Officer, Cyera
“Defenders have never faced a moment like this: attackers are compounding their capability, and for the first time we can compound ours. An open standard for how detection decisions get made – auditable, transparent, shared – is how trust gets built at industry scale. Adopting Detection Skills and helping shape it is what good digital citizenship looks like in the AI era.”
Read the announcement: https://vega.io/blog/vega-introduces-detection-skills · See it live: vega.io/get-a-demo
About the company: Vega is the pioneer of Agentic Cyber Defense. Built on the Security Analytics Mesh, the Vega platform, runs detection, triage, investigation, and tuning directly on data where it lives, at the speed the AI era demands: no data migration, no centralized data ingestion. Founded in 2024 and backed by Accel, Cyberstarts, Redpoint, and CRV with $185 million raised, Vega protects Fortune 200 enterprises, global banks, and leading healthcare providers.
Vega: Attacks scale. Defense compounds.
Contact Info:
Name: Dor Malul
Email: Send Email
Organization: Vega
Website: https://vega.io/
Release ID: 89199867
If you detect any issues, problems, or errors in this press release content, kindly contact error@releasecontact.com to notify us (it is important to note that this email is the authorized channel for such matters, sending multiple emails to multiple addresses does not necessarily help expedite your request). We will respond and rectify the situation in the next 8 hours.
