defensive-fast-triage

Automate SOC alert triage with severity matrices and escalation triggers.

1|Updated Apr 27, 2026
One-click install
npx skills add https://github.com/riparino/Claude-Cyber --skill defensive-fast-triage
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: defensive-fast-triage
Source: https://github.com/riparino/Claude-Cyber/tree/main/Claude-Blue/Skills/defensive-fast-triage
Command: npx skills add https://github.com/riparino/Claude-Cyber --skill defensive-fast-triage

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

Rapid SOC triage SOP: alert severity matrix, first-5-minutes checklist, escalation triggers, fast KQL queries. Covers shell-from-web-process, LSASS access, Defender disabled, AiTM sign-in. Use for L1/L2 analyst speed and alert prioritization.

Core Features & Use Cases

  • Triage Severity Matrix: defines actions by alert type and severity for quick decision making.
  • First 5 Minutes checklist: structured steps to scope, process-tree, network, and persistence checks.
  • KQL Examples: ready-to-use queries for common Defender and device events.
  • Escalation Triggers: clear criteria to escalate to IR or SecOps.

Quick Start

Load this skill during a security incident to guide rapid triage steps from alert to escalation.

Frequently Asked Questions about defensive-fast-triage

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I speed up SOC triage for Defender XDR alerts?

Speed up SOC triage by applying a structured severity matrix and a first-5-minutes checklist to rapidly prioritize Defender XDR alerts. This approach scopes alerts, checks process trees, and guides containment decisions for L1/L2 analysts.

What KQL queries should I use to detect LSASS access and credential abuse?

Use ready-to-run KQL examples targeting common device events to detect LSASS access and credential abuse. These queries help analysts quickly scope incidents and validate Defender alerts during the initial triage process.

When should I escalate a security incident to incident response teams?

Escalate a security incident to incident response teams when clear escalation triggers are met, such as AiTM sign-ins or Defender being disabled. Defined criteria ensure timely handoff from L1/L2 analysts to IR or SecOps.

What steps are needed for the first 5 minutes of incident response triage?

The first 5 minutes of incident response triage require structured steps to scope the alert, analyze the process tree, check network connections, and verify persistence mechanisms. This rapid checklist ensures immediate containment actions.

Can I use this triage checklist for shell detection from web processes?

Yes, you can use this triage checklist for shell detection from web processes. The SOP includes specific severity matrix actions and KQL examples for handling shell-from-web-process alerts within Defender and XDR environments.

Does this SOC triage SOP map alerts to MITRE ATT&CK techniques?

Yes, this SOC triage SOP maps alerts to MITRE ATT&CK techniques. It provides reference MITRE mappings alongside the severity matrix to give L1/L2 analysts context for prioritizing and responding to XDR security alerts.