soc-investigator

Automate DFIR investigations from SentinelOne alerts with configurable modes.

59|30|Updated Aug 19, 2025
One-click install
npx skills add https://github.com/Sentinel-One/ai-siem --skill soc-investigator
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: soc-investigator
Source: https://github.com/Sentinel-One/ai-siem/tree/main/plugins/s1-secops-skills/skills/soc-investigator
Command: npx skills add https://github.com/Sentinel-One/ai-siem --skill soc-investigator

SYSTEM DOCUMENTATION & REQUIREMENTS

💡 This Skill requires mgmt-console-api, powerquery, sdl-api, sdl-log-parser, sdl-dashboard, hyperautomation, purple-mcp, and includes scripts (resource) and references (resource) and assets (resource) components.

What problem does it solve?

This Skill addresses the complexity and manual work involved in conducting DFIR investigations by automating key processes, providing efficient workflows, and integrating with external data sources for comprehensive analysis.

Core Features & Use Cases

  • Automated DFIR Investigation: Orchestrates automated investigation processes with user intake and three investigation modes (SHORT/MEDIUM/LONG) based on SentinelOne alerts.
  • Third-Party Data Correlation: Optionally expands investigation into third-party data sources like M365, Entra, and Sharepoint for deeper correlation and anomaly detection.
  • MITRE ATT&CK Mapping: Automatically maps findings to MITRE ATT&CK for clearer context and analysis.

Quick Start

Run the 'soc-investigator' skill with the alert ID(s) you want to investigate.

Frequently Asked Questions about soc-investigator

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I automate DFIR investigations using SentinelOne alerts?

Automate DFIR investigations by running the skill with SentinelOne alert IDs, which triggers automated data retrieval, enrichment, and analysis through powerquery and integrated APIs. You receive enriched findings mapped to MITRE ATT&CK for clearer context.

Can I correlate third-party data sources like M365 and Entra during SOC analysis?

Yes, SOC analysis can optionally expand into third-party data sources like M365, Entra, and Sharepoint for deeper correlation and anomaly detection. This integration enriches the automated investigation workflow with broader telemetry context.

What investigation modes are available for SOC analysis automation?

SOC analysis automation supports SHORT, MEDIUM, and LONG investigation modes based on SentinelOne alerts. These modes dictate the depth of automated data retrieval and enrichment, allowing you to tailor the investigation scope to the alert's complexity.

Do I need specific APIs to run automated threat intelligence investigations?

Yes, automated threat intelligence investigations require dependencies including mgmt-console-api, powerquery, sdl-api, sdl-log-parser, sdl-dashboard, hyperautomation, and purple-mcp for full functionality. These APIs enable the underlying data retrieval and enrichment processes.

How does MITRE ATT&CK mapping work during automated DFIR investigations?

MITRE ATT&CK mapping is automatically applied to findings during the automated DFIR investigation process. This provides clearer context by aligning detected anomalies and behaviors with known adversary tactics and techniques.

What is the best way to streamline SOC analysis with Claude Cowork?

Streamline SOC analysis by orchestrating SentinelOne alerts with Claude Cowork's powerquery and APIs for automated data retrieval. This approach eliminates manual work by automating key processes and integrating external data sources for comprehensive analysis.

Related Skills