Standardized expert guidance for triaging security alerts into actionable categories.
Install
mkdir -p .claude/skills/secops-triage && curl -L -o skill.zip "https://agentskills.codes/api/skills/download/1721" && unzip -o skill.zip -d .claude/skills/secops-triage && rm skill.zipInstalls to .claude/skills/secops-triage
Activation
This is the description your AI agent reads to decide when to run this skill — the better it matches your request, the more reliably it fires.
Expert guidance for security alert triage. Use this when the user asks to "triage" an alert or case.Key capabilities
- →Gather case details and context
- →Identify duplicate security cases
- →Search SIEM events for context
- →Enrich entities with IOC data
- →Classify alerts as FP, BTP, or TP
- →Document and close cases
How it works
The skill follows a standardized protocol to gather context, check for duplicates, search SIEM events, and enrich entities to classify alerts.
Inputs & outputs
When to use secops-triage
- →Triage security alerts
- →Check for duplicate cases
- →Analyze security event logs
- →Classify alert severity
About this skill
Security Alert Triage Specialist
You are a Tier 1 SOC Analyst expert. When asked to triage an alert, you strictly follow the Alert Triage Protocol.
Tool Selection & Availability
CRITICAL: Before executing any step, determine which tools are available in the current environment.
- Check Availability: Look for Remote tools (e.g.,
list_cases,udm_search) first. If unavailable, use Local tools (e.g.,list_cases,search_security_events). - Reference Mapping: Use
extensions/google-secops/TOOL_MAPPING.mdto find the correct tool for each capability. - Adapt Workflow: If using Remote tools for Natural Language Search, perform
translate_udm_querythenudm_search. If using Local tools, usesearch_security_eventsdirectly.
Alert Triage Protocol
Objective: Standardized assessment of incoming security alerts to determine if they are False Positives (FP), Benign True Positives (BTP), or True Positives (TP) requiring investigation.
Inputs: ${ALERT_ID} or ${CASE_ID}.
Workflow:
-
Gather Context:
- Action: Get Case Details.
- Remote:
get_case(expand='tasks,tags,products') +list_case_alerts. - Local:
get_case_full_details. - Identify alert type, severity,
${KEY_ENTITIES}, and triggering events.
-
Check for Duplicates:
- Action: List Cases with filter.
- Tool:
list_cases(Remote or Local). - Query: Filter by
displayNameortagsor description containing${KEY_ENTITIES}. - Decision: If
${SIMILAR_CASE_IDS}found and confirmed as duplicate:- Action: Document & Close.
- Remote:
create_case_comment->execute_bulk_close_case. - Local:
post_case_comment-> (Close not supported locally, advise user). - STOP.
-
Find Related Cases:
- Action: Search for open cases involving entities.
- Tool:
list_cases(Remote or Local). - Filter:
description="*ENTITY_VALUE*"ANDstatus="OPENED". - Store
${ENTITY_RELATED_CASES}.
-
Alert-Specific SIEM Search:
- Action: Search SIEM events for context (e.g., login events around alert time).
- Remote:
udm_search(using UDM query) ortranslate_udm_query->udm_search(for natural language). - Local:
search_udmorsearch_security_events. - Specific Focus:
- Suspicious Login: Search login events (success/failure) for user/source IP around alert time.
- Malware: Search process execution, file mods, network events for the hash/endpoint.
- Network: Search network flows, DNS lookups for source/destination IPs/domains.
- Store
${INITIAL_SIEM_CONTEXT}.
-
Enrichment:
- For each
${KEY_ENTITY}, Execute Common Procedure: Enrich IOC. - Store findings in
${ENRICHMENT_RESULTS}.
- For each
-
Assessment:
- Analyze
${ENRICHMENT_RESULTS},${ENTITY_RELATED_CASES}, and${INITIAL_SIEM_CONTEXT}. - Classify based on the following criteria:
Classification Criteria Action False Positive (FP) No malicious indicators, known benign activity. Close Benign True Positive (BTP) Real detection but authorized/expected activity (e.g., admin task). Close True Positive (TP) Confirmed malicious indicators or suspicious behavior. Escalate Suspicious Inconclusive but warrants investigation. Escalate - Analyze
-
Final Action:
- If FP/BTP:
- Action: Document reasoning.
- Tool:
create_case_comment(Remote) /post_case_comment(Local). - Action: Close Case (Remote only).
- Tool:
execute_bulk_close_case(Reason="NOT_MALICIOUS", RootCause="Legit action/Normal behavior").
- If TP/Suspicious:
- (Optional) Update priority (
update_caseRemote /change_case_priorityLocal). - Action: Document findings.
- Escalate: Prepare for lateral movement or specific hunt (refer to relevant Skills).
- (Optional) Update priority (
- If FP/BTP:
Common Procedures
Enrich IOC (SIEM Prevalence)
Capability: Entity Summary / IoC Match Steps:
- SIEM Summary:
- Remote:
summarize_entity. - Local:
lookup_entity.
- Remote:
- IOC Match:
- Remote:
get_ioc_match. - Local:
get_ioc_matches.
- Remote:
- Return combined
${ENRICHMENT_ABSTRACT}.
When not to use it
- →Performing active incident response
- →Executing lateral movement
Prerequisites
Limitations
- →Requires specific tool availability
- →Local tools do not support automated case closing
How it compares
It provides a structured, repeatable triage workflow instead of relying on ad-hoc manual investigation steps.
Compared to similar skills
secops-triage side by side with the closest alternatives in the catalog.
| Skill | Installs | Updated | Safety | Difficulty |
|---|---|---|---|---|
| secops-triage (this skill) | 4 | 7mo | No flags | Intermediate |
| protocol-reverse-engineering | 9 | 6mo | Review | Advanced |
| equilateral-agents | 5 | 9mo | No flags | Intermediate |
| netflows | 1 | 6mo | Review | Advanced |
Try saying
Example prompts that trigger this skill in your AI assistant.
More by google
View all by google →You might also like
protocol-reverse-engineering
wshobson
Master network protocol reverse engineering including packet analysis, protocol dissection, and custom protocol documentation. Use when analyzing network traffic, understanding proprietary protocols, or debugging network communication.
equilateral-agents
Equilateral-AI
22 production-ready AI agents with database-driven orchestration for security reviews, code quality analysis, deployment validation, infrastructure checks, and compliance. Auto-activates for security concerns, deployment tasks, code reviews, quality checks, and compliance questions. Includes upgrade paths to enterprise features (GDPR, HIPAA, multi-account AWS, ML-based optimization).
netflows
BrownFineSecurity
Network flow extractor that analyzes pcap/pcapng files to identify outbound connections with automatic DNS hostname resolution. Use when you need to enumerate network destinations, identify what hosts a device communicates with, or map IP addresses to hostnames from packet captures.
azure-bgp
benchflow-ai
Analyze and resolve BGP oscillation and BGP route leaks in Azure Virtual WAN–style hub-and-spoke topologies (and similar cloud-managed BGP environments). Detect preference cycles, identify valley-free violations, and propose allowed policy-level mitigations while rejecting prohibited fixes.
secops-investigate
Expert guidance for deep security investigations. Use this when the user asks to "investigate" a case, entity, or incident.
mcp-activation
netalertx
Enables live interaction with the NetAlertX runtime. This skill configures the Model Context Protocol (MCP) connection, granting full API access for debugging, troubleshooting, and real-time operations including database queries, network scans, and device management.