⚡AgentSkills
🛡️ Cyber Defense & SOC · SOC Operations

Triage alerts with consistent depth

Enrichment order, true/false-positive calls with evidence, and escalation criteria applied identically every shift.

foundation~25 minSOC AnalystsDetection EngineersThreat Hunters

Steps

  1. 1Pull alert context first: entity history, related alerts last 7 days
  2. 2Enrich systematically: IP reputation, hash verdicts, identity risk, asset criticality
  3. 3Validate against known-change calendar before calling malicious
  4. 4Classify with evidence links attached — no verdict without artifact
  5. 5Escalate by blast radius criteria written down, not gut feel
  6. 6Log analyst notes reusable by the next person

Common Pitfalls

  • ▲Auto-closing batches to clear the queue before events
  • ▲Verdicts without captured evidence being unreproducible

Commands

Install with skills CLI
$ npx skills add aniruddhaadak80/skills --skill soc-operations-alert-triage-discipline
Install globally
$ npx skills add aniruddhaadak80/skills --skill soc-operations-alert-triage-discipline -g

Tags

#triage#soc#enrichment#cyber-defense-ops#soc-operations

Related skills

Structured hunts starting from TTP intelligence, producing detections or documented negatives.

🛡️ Cyber Defense & SOC·~45m

Inventory what you can see versus what attacks require, closing blind spots deliberately.

🛡️ Cyber Defense & SOC·~35m