What problem does it solve?
Security operations teams need a repeatable, transparent process to triage alerts and cases, identify false positives, benign true positives, and true positives, and decide when to escalate or close.
Core Features & Use Cases
- Standardized Alert Triage Protocol that guides context gathering, duplicate detection, related cases lookup, SIEM enrichment, and final actions.
- Supports remote and local tooling workflows to determine escalation paths and next steps in incident response.
- Use Case: A newly surfaced alert is quickly assessed for legitimacy, linked to existing cases, enriched with SIEM context, and either closed or escalated for investigation.
Quick Start
Provide an ALERT_ID or CASE_ID to begin triage of an alert or case. The skill will guide you through context gathering, duplication checks, SIEM enrichment, enrichment, and final actions.