full-investigation

Orchestrate Tier 2/3 investigations with IOC analysis, triage, and reporting.

120|34|Updated May 9, 2025
One-click install
npx skills add https://github.com/dandye/ai-runbooks --skill full-investigation
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: full-investigation
Source: https://github.com/dandye/ai-runbooks/tree/main/skills/_workflows/full-investigation
Command: npx skills add https://github.com/dandye/ai-runbooks --skill full-investigation

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

Escalated security investigations require coordinating multiple analyses, triage steps, and documentation. This workflow automates the orchestration, reducing handoffs and time to resolution.

Core Features & Use Cases

  • End-to-end investigation orchestration across IOC deep-dives, correlation, and reporting
  • Dynamic routing to specialized triage steps based on alert type
  • Comprehensive documentation and handoff for IR when escalation is needed

Quick Start

Start the Full Investigation workflow by providing CASE_ID and optionally PRIMARY_IOCS to initiate the run.

Frequently Asked Questions about full-investigation

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I orchestrate end-to-end Tier 2/3 security investigations?

You can orchestrate end-to-end Tier 2/3 security investigations by initiating the workflow with a CASE_ID and optional PRIMARY_IOCS. It automatically coordinates intake, routing, IOC analysis, triage, and reporting to streamline resolution.

What is the best way to automate triage and reporting for escalated incident response cases?

Automating triage and reporting for escalated incident response cases is achieved through dynamic routing based on alert type. The workflow enforces required steps, handles correlation, and generates a final investigation report and disposition.

Can I use this workflow to correlate malware, authentication, and network alerts?

Yes, you can use this workflow to correlate malware, authentication, and network alerts. It dynamically routes escalated security cases to specialized triage steps and expands the analysis before documentation.

Does this investigation orchestration integrate with SIEM and IR workflows?

This investigation orchestration integrates directly with GTI, SIEM, and IR workflows. It ensures comprehensive documentation and seamless handoff for incident response when escalation is needed.

How do I start an investigation run for IOC deep-dives?

To start an investigation run for IOC deep-dives, provide a CASE_ID and optionally PRIMARY_IOCS. This initiates the orchestration, enforcing required steps for intake, correlation, and final reporting.