zins-investigate-security-incident

Correlate Zscaler Z-Insights security data sources into a structured incident timeline.

44|24|Updated May 29, 2025
One-click install
npx skills add https://github.com/zscaler/zscaler-mcp-server --skill zins-investigate-security-incident
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: zins-investigate-security-incident
Source: https://github.com/zscaler/zscaler-mcp-server/tree/main/skills/zins/investigate-security-incident
Command: npx skills add https://github.com/zscaler/zscaler-mcp-server --skill zins-investigate-security-incident

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

Correlates multiple security data sources to provide a coherent timeline and context for security incidents, accelerating detection, investigation, and response.

Core Features & Use Cases

  • Correlates threat analytics, cyber incidents, firewall actions, web traffic patterns, and shadow IT findings to produce a unified incident timeline.
  • Guides incident responders through evidence gathering, trend analysis, and containment decisions.
  • Use Case: When a security analyst needs to investigate a detected threat, assess incident scope, and understand data exfiltration or shadow IT involvement.

Quick Start

Use the zins-investigate-security-incident skill to generate a complete incident timeline for a specified security alert.

Frequently Asked Questions about zins-investigate-security-incident

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I build a security incident timeline from multiple data sources?

To build a security incident timeline, you correlate threat analytics, cyber incidents, firewall actions, web traffic patterns, and shadow IT findings to produce a unified, chronological incident report for investigation.

What is the best way to investigate shadow IT findings during a security incident?

Investigating shadow IT findings involves correlating unauthorized application data with firewall actions and web traffic patterns to assess incident scope and understand potential data exfiltration risks.

Can I analyze firewall actions and web traffic patterns together for threat analysis?

Yes, you can analyze firewall actions and web traffic patterns together by correlating these data sources to guide incident responders through evidence gathering, trend analysis, and containment decisions.

Do I need access to threat analytics data to investigate an incident with this approach?

Yes, investigating an incident requires access to threat analytics, cyber incidents, firewall, web traffic, and shadow IT data sources to successfully generate a complete incident timeline.

What limitations exist when analyzing incident trends across Zscaler Z-Insights?

Analysis is limited to the data available within Zscaler Z-Insights, requiring comprehensive access to threat analytics, firewall, web traffic, and shadow IT sources to produce a complete incident timeline.

When do I need to correlate threat analytics for incident response?

You need to correlate threat analytics for incident response when a security analyst detects a threat, requiring a coherent timeline to accelerate detection, investigation, and containment decisions.