🛡️ Cyber Defense & SOC · SOC Operations
Triage alerts with consistent depth
Enrichment order, true/false-positive calls with evidence, and escalation criteria applied identically every shift.
foundation~25 minSOC AnalystsDetection EngineersThreat Hunters
Steps
- 1Pull alert context first: entity history, related alerts last 7 days
- 2Enrich systematically: IP reputation, hash verdicts, identity risk, asset criticality
- 3Validate against known-change calendar before calling malicious
- 4Classify with evidence links attached — no verdict without artifact
- 5Escalate by blast radius criteria written down, not gut feel
- 6Log analyst notes reusable by the next person
Common Pitfalls
- ▲Auto-closing batches to clear the queue before events
- ▲Verdicts without captured evidence being unreproducible
Commands
Install with skills CLI
$ npx skills add aniruddhaadak80/skills --skill soc-operations-alert-triage-disciplineInstall globally
$ npx skills add aniruddhaadak80/skills --skill soc-operations-alert-triage-discipline -gTags
#triage#soc#enrichment#cyber-defense-ops#soc-operations