defensive-soc-workflows

Standardize SOC triage, escalation, and shift handoff workflows.

1|Updated Apr 27, 2026
One-click install
npx skills add https://github.com/riparino/Claude-Cyber --skill defensive-soc-workflows
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: defensive-soc-workflows
Source: https://github.com/riparino/Claude-Cyber/tree/main/Claude-Blue/Skills/defensive-soc-workflows
Command: npx skills add https://github.com/riparino/Claude-Cyber --skill defensive-soc-workflows

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

Standardizes and automates SOC triage and escalation processes to reduce MTTR and ensure consistent handling of alerts across teams.

Core Features & Use Cases

  • Alert Triage SOP: consistent intake and initial classification.
  • Escalation Matrix: defined SLAs and escalation paths for L1/L2/L3.
  • SOAR Automation: integration patterns to automate enrichment and containment.
  • Shift Handoff: documented open incidents and next steps for seamless transitions.
  • KQL Guidance: open incidents, alert queue, and performance dashboards.
  • Use Case: implement for 24/7 SOC operations across multiple regions.

Quick Start

Load the SOC Workflows skill and apply the Alert Triage SOP to triage the latest incident and document next actions.

Frequently Asked Questions about defensive-soc-workflows

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I standardize SOC triage and escalation workflows for L1/L2/L3 analysts?

Standardize SOC triage and escalation workflows by applying a consistent intake SOP and an escalation matrix with defined SLAs for L1, L2, and L3 analysts. This ensures consistent alert handling and reduces mean time to respond across security operations.

What is the best way to automate incident escalation paths in a 24/7 SOC?

Automate incident escalation paths in a 24/7 SOC by implementing an escalation matrix with defined SLAs and SOAR integration patterns. This automates alert enrichment and containment while ensuring seamless shift handoffs with documented open incidents.

How do I create KQL queries for SOC alert queues and performance dashboards?

Create KQL queries for SOC alert queues and performance dashboards using provided KQL guidance tailored for open incidents and alert triage. This helps monitor security operations metrics and track mean time to respond across shift handoffs.

Can I use this SOC workflow skill for multi-region 24/7 security operations?

Yes, you can use this SOC workflow skill for multi-region 24/7 security operations. It is designed to implement standard operating procedures and escalation matrices across distributed teams, ensuring consistent alert triage and seamless shift handoffs globally.

How do I document shift handoffs for open security incidents?

Document shift handoffs for open security incidents by applying the documented workflow steps provided for seamless transitions. This ensures incoming analysts receive documented open incidents and next actions, reducing context loss during L1/L2/L3 triage handoffs.

Does the skill provide SOAR integration patterns for alert enrichment and containment?

Yes, the skill provides SOAR integration patterns to automate alert enrichment and containment during the SOC triage process. These patterns integrate directly into the escalation matrix to reduce manual effort and standardize incident response actions.