triaging-security-incident

Automate security incident triage using NIST SP 800-61r3 and SANS PICERL frameworks.

2|Updated Jun 5, 2026
One-click install
npx skills add https://github.com/balsm-health/Balsm-AI --skill triaging-security-incident
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: triaging-security-incident
Source: https://github.com/balsm-health/Balsm-AI/tree/main/plugin/skills/triaging-security-incident
Command: npx skills add https://github.com/balsm-health/Balsm-AI --skill triaging-security-incident

SYSTEM DOCUMENTATION & REQUIREMENTS

💡 This Skill requires requests, json, datetime, base64, and includes scripts (resource) and references (resource) components.

What problem does it solve?

This Skill automates the triage and initial analysis of security incidents, helping to determine severity, scope, and response actions quickly and efficiently.

Core Features & Use Cases

  • Incident Triage: Classifies incidents, assigns severity based on business impact, and routes to appropriate response teams.
  • Data Analysis: Collects and enriches alert data, checks against threat intelligence, and identifies patterns for further analysis.
  • Report Generation: Documents the triage process and generates a structured report with actionable recommendations.

Quick Start

Use the triaging-security-incident skill to triage the new alert received at 'alert-1234'.

Frequently Asked Questions about triaging-security-incident

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I automate security incident triage using NIST and SANS frameworks?

Automate security incident triage by classifying alerts, assigning severity based on business impact, and routing incidents to response teams using the NIST SP 800-61r3 and SANS PICERL frameworks to determine scope and response actions quickly.

What is the SANS PICERL framework for incident response triage?

The SANS PICERL framework structures incident response into Preparation, Identification, Containment, Eradication, Recovery, and Lessons Learned phases. This Skill uses it alongside NIST SP 800-61r3 to automate the initial identification, prioritization, and triage of security incidents.

Do I need SIEM and EDR platform access for security incident triage?

Yes, security incident triage requires access to SIEM and EDR platforms, threat intelligence services, and asset inventories to collect and enrich alert data, identify patterns, and generate actionable triage reports.

How do I generate a structured triage report for a new cybersecurity alert?

Generate a structured triage report by passing a new alert to the triage process, which collects alert data, checks it against threat intelligence, assigns severity based on business impact, and documents actionable recommendations.

Can I integrate threat intelligence services to prioritize security incidents?

Yes, you can integrate threat intelligence services to enrich collected alert data, identify patterns for further analysis, and accurately prioritize security incidents based on their scope and business impact.