What problem does it solve?
Security teams often lack a structured, tested framework for routing incidents to the right responders, causing critical alerts to sit in unwatched queues, SLAs to be missed, and P1 incidents to go unacknowledged overnight.
Core Features & Use Cases
- Tiered SOC Structure: Defines Tier 1 triage, Tier 2 investigation, Tier 3 threat hunting, and management escalation roles with clear responsibilities.
- Severity Classification with SLAs: Provides P1-P4 severity tables with response times, resolution targets, and communication cadences.
- Context-Driven Escalation: Combines severity with asset criticality in a decision matrix, plus automatic and time-based escalation triggers.
- SOAR Integration: Includes XSOAR playbook trigger examples and auto-escalation rules for hands-free routing.
- Use Case: A SOC manager building a 24x7 operation uses this Skill to define that ransomware detection auto-escalates to Tier 3 plus management within 15 minutes, with a verified on-call rotation backing every tier.
Quick Start
Ask the AI to build a SOC escalation matrix with P1-P4 severity tiers, response SLAs, and automatic escalation triggers for a 24x7 security operations team.