What problem does it solve? New SOC analysts often lack a repeatable method for triaging incidents and producing reports that a SOC lead would accept. This Skill walks a learner through one real or simulated Microsoft Defender XDR incident end-to-end, building the muscle memory of alert triage, entity scoping, timeline construction, and incident report writing within a realistic time-box. ## Core Features & Use Cases - Structured five-phase investigation: Walks alerts, entities, evidence, timeline, and impact assessment in Defender XDR, then classifies and closes the incident with proper tags and summary. - IR report template: Produces a one-page markdown incident report with Summary, Scope, Alerts, Timeline, Root cause, and Recommended actions sections. - KQL timeline hunting: Includes an Advanced Hunting query to bracket the attack window and find the earliest known compromise (patient zero). - Use Case: A cybersecurity student who just onboarded a VM to Defender for Endpoint runs an evaluation attack, then uses this Skill to triage the resulting incident, classify it as a true positive (penetration test), and deliver a SOC-ready IR report in about 75 minutes. ## Quick Start Ask the mentor to start the cso-incident-investigation project and walk you through triaging an active incident in the Defender XDR portal into a one-page IR report.