Classifies and prioritizes security incidents using structured IR playbooks and SIEM/case-management queries (Splunk, TheHive) to determine severity, assign response teams, and initiate the appropriate response procedures. Use when a new SOC alert needs triage, multiple concurrent incidents require prioritization, or automated triage rules need validation or tuning.
Standardmäßig ist der Prompt ausgewählt, der zuerst die Quelle prüft. Sie können zu einem direkten Befehl wechseln oder eine lokale Kopie herunterladen.
Quelldateien prüfen
Lesen Sie SKILL.md und alle von SkillsMP angezeigten Begleitdateien, bevor Sie sich für eine Installation entscheiden.
Mit Codex oder Claude installieren Kopieren Sie diesen Prompt, fügen Sie ihn in Codex, Claude oder einen anderen Assistant ein und lassen Sie die Skill-Seite prüfen und installieren.
Ein direkter Befehl überspringt den Prüf-Prompt. Prüfen Sie die Quelle, bevor Sie ihn ausführen.
Classifies and prioritizes security incidents using structured IR playbooks and SIEM/case-management queries (Splunk, TheHive) to determine severity, assign response teams, and initiate the appropriate response procedures. Use when a new SOC alert needs triage, multiple concurrent incidents require prioritization, or automated triage rules need validation or tuning.
Alert correctly identifying a real security incident
False Positive
Alert incorrectly flagging benign activity as malicious
Severity Classification
Ranking incident priority based on impact and urgency
Playbook Selection
Choosing the appropriate response procedure based on incident type
IOC Enrichment
Adding context to indicators from threat intelligence sources
Escalation Threshold
Criteria triggering escalation to higher severity or management
Triage SLA
Time target for initial assessment (typically 15-30 min for critical)
Tools & Systems
Tool
Purpose
Splunk/Elastic/QRadar
SIEM alert correlation and querying
TheHive/SIRP
Incident case management and playbook tracking
VirusTotal/AbuseIPDB
IOC reputation and enrichment
PagerDuty/OpsGenie
On-call management and alerting
MITRE ATT&CK
Technique classification and mapping
Cortex XSOAR
SOAR platform for automated triage workflows
Common Scenarios
Brute Force Alert: Multiple failed logins from single IP. Enrich IP reputation, check geo-location, verify if account was compromised, assign P3 if unsuccessful.
Malware Detection on Endpoint: AV/EDR quarantined malware. Verify quarantine success, check for lateral movement, assign P2 if persistence detected.
Suspicious Outbound Traffic: Large data transfer to unknown external IP. Check if known cloud service, verify data classification, assign P1 if exfiltration confirmed.
Phishing Email Reported: User reports suspicious email. Extract IOCs, check if others received it, assign P2 if credentials were entered.
Privilege Escalation: User gained admin rights unexpectedly. Verify if authorized change, check for exploitation, assign P1 if unauthorized.
Output Format
Triage decision document with severity justification
Incident ticket with assigned playbook and team
IOC enrichment summary attached to case
Escalation notification to appropriate stakeholders