What problem does it solve?
This Skill prevents inconsistent SOC work by turning alert triage, threat hunting, and incident investigation into repeatable, auditable engagement workflows mapped to real frameworks.
Core Features & Use Cases
- Tier 1–3 operational workflows: Guides SOC analysts through alert disposition, context building, hunting execution, containment-first incident response, and post-incident improvements.
- Framework-grounded decisioning: Uses MITRE ATT&CK, NIST SP 800-61r2, and Lockheed Martin Cyber Kill Chain to structure findings and map analysis outputs.
- Closed-loop detection improvement: Turns hunts and incidents into detection rule updates and validates changes via re-triage.
- Deliverable templates: Provides ready-to-use formats for alert disposition reports, incident timelines, and threat hunt reports.
Quick Start
Use the soc-analyst role bundle to guide an investigation from a new alert through log correlation, CVE triage (when applicable), and an evidence-ready escalation decision.