LAS VEGAS – Black Hat USA 2026 – August 4, 2026 – Vega, the pioneer of Agentic Cyber Defense, today launched Detection Skills: an open standard that redefines security operations for the AI era. The standard captures a team’s expert judgment as a self-improving agentic loop across detection, triage, and investigation. Available to the community as an open standard, or natively within the best-in-class Vega platform, they allow modern Cyber Defense Engineers to architect their reasoning once and scale it across everything they defend. It gives every company an answer to the question that matters most: can our defense keep pace with AI?
Why Now
Frontier AI has collapsed the economics of cyberattacks. Intrusions that took skilled teams weeks now take minutes, with advanced models breaking containment and autonomously breaching organizations. Defenses built on legacy SIEM have not kept pace: they can only recognize known patterns in a threat landscape where attacks are generated, not repeated.
Just as Sigma defined the traditional detection rule format, Detection Skills is what comes next for AI-first Cyber Defense teams. The engineer who builds a detection and the analyst who answers it at 2 a.m. often never meet, and the context dies in the handoff.
- Detect and decide at AI speed. Triage and investigations run automatically the moment a detection fires, slashing MTTD and MTTR. Only what matters reaches a human, with a finished, evidence-backed workbook attached.
- Scale cyber defense expertise. Author a skill once and the same judgment reaches every alert, known or unknown. Engineers keep complete transparency and control over the AI’s reasoning: what it checked, why it decided, and no change without their sign-off.
Adopt without disruption. Works alongside existing security investments. It launches with the Agentic Detection Library: 50+ skills from Vega Research and our partners, plus a sandbox to build, test, and export spec-compliant detections, and GitHub to contribute your own. .
Supporting quotes:
“We adopted Detection Skills early and started by encoding our own triage logic, the way our team actually works an alert, not a generic playbook. Every skill we ship gives us more explicit control over what the AI checks, escalates, and dismisses. The result is a queue we trust: fewer false positives, and every verdict arrives with its reasoning attached.”
“Retail runs on peak moments, and attackers know exactly when those are. My team cannot be the constraint on a Saturday in December. Detection Skills gives us leverage we can plan around: the expertise is written down, it runs on every alert, and it holds up when volume spikes. We are adopting it and sharing what we learn, because no security team should have to rebuild this work alone.”
“Defenders have never faced a moment like this: attackers are compounding their capability, and for the first time we can compound ours. An open standard for how detection decisions get made – auditable, transparent, shared – is how trust gets built at industry scale. Adopting Detection Skills and helping shape it is what good digital citizenship looks like in the AI era.”