defensive-security-analyst

Guide alert triage, investigation, and containment planning for SOC operations.

7|1|Updated May 19, 2026
One-click install
npx skills add https://github.com/daemon-blockint-tech/Agentic-Enteprises-Skill --skill defensive-security-analyst
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: defensive-security-analyst
Source: https://github.com/daemon-blockint-tech/Agentic-Enteprises-Skill/tree/main/defensive-security-analyst
Command: npx skills add https://github.com/daemon-blockint-tech/Agentic-Enteprises-Skill --skill defensive-security-analyst

SYSTEM DOCUMENTATION & REQUIREMENTS

💡 This Skill includes references (resource) components.

What problem does it solve?

Guides defensive security analysis—alert triage, log and SIEM investigation, threat hunting, detection engineering basics, MITRE ATT&CK mapping, incident scoping, containment recommendations, and DFIR evidence handling for SOC and blue-team analysts.

Core Features & Use Cases

  • Structured alert triage workflows for SIEM/EDR integration
  • Timeline construction, evidence collection, and IOC documentation
  • Detection engineering templates with ATT&CK mapping guidance
  • Threat hunting workflows and IR handoff templates

Quick Start

Analyze a suspicious alert and generate a structured incident report.

Frequently Asked Questions about defensive-security-analyst

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I streamline SOC triage and incident response workflows?

Streamline SOC triage by following structured alert investigation workflows that guide log analysis, evidence collection, and incident containment planning for security operations.

How do I map security alerts to MITRE ATT&CK techniques during threat hunting?

Map security alerts to MITRE ATT&CK techniques using detection engineering templates and threat hunting workflows that translate suspicious log activity into structured adversary behavior mapping.

What is the best way to build an incident timeline from SIEM and EDR logs?

Build an incident timeline from SIEM and EDR logs by sequencing alert triggers and endpoint telemetry, collecting evidence, and documenting indicators of compromise for structured reporting.

Can I use this for DFIR evidence handling and incident handoffs?

Yes, you can use it for DFIR evidence handling and incident handoffs, as it provides best-practice workflows for evidence collection, incident scoping, and structured handoff reporting.

Does this workflow support threat hunting across SIEM and EDR platforms?

Yes, this workflow supports threat hunting across SIEM and EDR platforms by guiding structured investigation of logs and endpoint telemetry to uncover hidden threats and document findings.

Why do I need a structured workflow for alert triage and incident scoping?

You need a structured workflow for alert triage and incident scoping to ensure consistent evidence handling, accurate MITRE ATT&CK mapping, and reliable containment recommendations during incident response.