secops-investigate

Guide security incident investigations with procedures for enrichment, synthesis, and reporting.

513|130|Updated Apr 2, 2025
One-click install
npx skills add https://github.com/google/mcp-security --skill secops-investigate
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: secops-investigate
Source: https://github.com/google/mcp-security/tree/main/extensions/google-secops/skills/investigate
Command: npx skills add https://github.com/google/mcp-security --skill secops-investigate

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

This Skill provides expert guidance for conducting thorough security investigations when users ask to investigate a case, entity, or incident.

Core Features & Use Cases

  • Step-by-step investigation procedures for common security scenarios such as malware, lateral movement, and case closure.
  • Tool-agnostic guidance on selecting between remote tools and local data sources, using reference mappings, and performing enrichment and case correlation.
  • Documentation and reporting guidelines for generating SOAR entries and formal investigation reports.

Quick Start

Ask the assistant to start an investigation on a specific case or entity. For example: Investigate CASE_ID for a suspected malware incident and summarize findings.

Frequently Asked Questions about secops-investigate

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I conduct a security investigation for a suspected malware incident?

To conduct a security investigation, initiate the process by providing a case ID or entity. The system guides you through step-by-step procedures for malware analysis, remote tool selection, evidence gathering, and formal reporting.

What is the standard procedure for incident response case closure?

Incident response case closure requires synthesizing enriched data and documenting findings. The procedure specifies generating formal investigation reports and creating SOAR entries to ensure all evidence and case correlations are officially recorded.

How do I choose between remote tools and local data sources during forensics?

Choosing between remote tools and local data sources during forensics relies on reference mappings. The system provides tool-agnostic guidance to select appropriate access methods for evidence gathering and case correlation.

Can I use this for investigating lateral movement within a SOC environment?

Yes, you can use this for investigating lateral movement within a SOC environment. It provides step-by-step investigation procedures for common security scenarios including lateral movement, malware, and case management.

How do I document and report findings from an incident response investigation?

To document and report findings from an incident response investigation, follow the built-in documentation guidelines. These specify how to generate SOAR entries and compile formal investigation reports based on synthesized evidence.

What do I need to start an expert-guided security investigation?

To start an expert-guided security investigation, you need a specific case ID or entity to investigate. The system then applies standard procedures for enrichment, synthesis, and documentation based on your initial input.