soc-analyst

Guide SOC analysts through structured alert triage and incident investigation workflows.

44|128|Updated Mar 6, 2026
One-click install
npx skills add https://github.com/UnitOneAI/SecuritySkills --skill soc-analyst
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: soc-analyst
Source: https://github.com/UnitOneAI/SecuritySkills/tree/main/roles/soc-analyst
Command: npx skills add https://github.com/UnitOneAI/SecuritySkills --skill soc-analyst

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

This Skill prevents inconsistent SOC work by turning alert triage, threat hunting, and incident investigation into repeatable, auditable engagement workflows mapped to real frameworks.

Core Features & Use Cases

  • Tier 1–3 operational workflows: Guides SOC analysts through alert disposition, context building, hunting execution, containment-first incident response, and post-incident improvements.
  • Framework-grounded decisioning: Uses MITRE ATT&CK, NIST SP 800-61r2, and Lockheed Martin Cyber Kill Chain to structure findings and map analysis outputs.
  • Closed-loop detection improvement: Turns hunts and incidents into detection rule updates and validates changes via re-triage.
  • Deliverable templates: Provides ready-to-use formats for alert disposition reports, incident timelines, and threat hunt reports.

Quick Start

Use the soc-analyst role bundle to guide an investigation from a new alert through log correlation, CVE triage (when applicable), and an evidence-ready escalation decision.

Frequently Asked Questions about soc-analyst

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I structure SOC alert triage and incident investigation workflows?

Structured SOC alert triage requires following defined engagement-type sequences mapped to MITRE ATT&CK and NIST SP 800-61r2. This ensures consistent, auditable deliverables like alert disposition reports and incident timelines without skipping containment steps.

How does threat hunting map to MITRE ATT&CK and Cyber Kill Chain frameworks?

Threat hunting maps to MITRE ATT&CK and Lockheed Martin Cyber Kill Chain frameworks to structure analysis outputs. This approach transforms raw hypothesis testing into closed-loop detection rule updates validated via re-triage.

What is the best way to build an incident timeline for security operations?

Building an incident timeline requires using structured deliverable templates during containment-first incident response. This enforces adherence to NIST SP 800-61r2, ensuring the final timeline is evidence-ready for escalation decisions.

Can I use this for Tier 1 through Tier 3 security operations tasks?

Yes, this handles Tier 1 through Tier 3 security operations tasks. It guides SOC analysts from initial alert disposition and context building through hunting execution, containment-first incident response, and post-incident detection engineering.

How do I turn threat hunts and incident findings into detection engineering improvements?

Turn threat hunts and incidents into detection engineering improvements through a closed-loop process. This converts investigation findings into detection rule updates and validates the newly engineered rules via re-triage to ensure accurate alert disposition.