Triaging Security IncidentCAUTION
817 structured cybersecurity skills for AI agents · Mapped to 6 frameworks: MITRE ATT&CK, NIST CSF 2.0, MITRE ATLAS, D3FEND, NIST AI RMF & MITRE F3 (Fight Fraud) · agentskills.io standard · Works with Claude Code, GitHub Copilot, Codex CLI, Cursor, Gemini CLI & 20+ platforms · 29 security domains ·
Overview
817 structured cybersecurity skills for AI agents · Mapped to 6 frameworks: MITRE ATT&CK, NIST CSF 2.0, MITRE ATLAS, D3FEND, NIST AI RMF & MITRE F3 (Fight Fraud) · agentskills.io standard · Works with Claude Code, GitHub Copilot, Codex CLI, Cursor, Gemini CLI & 20+ platforms · 29 security domains ·
6c59587be632OBSERVED · 2026-10-07What it tells the agent
The instruction file, verbatim from the audited commit — this is the text the model reads, and the surface the audit's instruction layer examines. Quoted here so you can judge it without cloning anything.
--- name: triaging-security-incident description: 'Performs initial triage of security incidents using the NIST SP 800-61r3 and SANS PICERL frameworks, classifying incident type, assigning priority by business impact, and routing to the appropriate response team. Use when a SIEM/EDR alert needs human classification, concurrent alerts must be prioritized, or a user report or threat-intel IOC match requires initial incident categorization.' domain: cybersecurity subdomain: incident-response tags: - incident-triage - NIST-800-61 - SANS-PICERL - severity-classification - SOC-operations mitre_attack: - T1486 - T1490 - T1070 - T1078 version: 1.0.0 author: mahipal license: Apache-2.0 d3fend_techniques: - Executable Denylisting - Execution Isolation - File Metadata Consistency Validation - Content Format Conversion - File Content Analysis nist_csf: - RS.MA-01 - RS.MA-02 - RS.AN-03 - RC.RP-01 --- # Triaging Security Incidents ## When to Use - A SIEM or EDR alert fires and requires human classification before escalation - Multiple concurrent alerts arrive and the SOC must prioritize response order - An end user reports suspicious activity and the incident needs initial categorization - A threat intelligence feed matches an IOC observed in the environment **Do not use** for routine vulnerability scanning results or compliance audit findings that do not represent active security incidents. ## Prerequisites - Access to SIEM platform (Splunk, Elastic, Microsoft Sentinel) with current alert data - Incident classification taxonomy aligned to NIST SP 800-61r3 categories - Predefined severity matrix mapping asset criticality to threat type - Contact roster for escalation paths (Tier 1 through Tier 3 and CIRT) - Asset inventory with business criticality ratings ## Workflow ### Step 1: Collect Initial Alert Data Gather all available context from the triggering alert before making classification decisions: - **Alert source**: Which detection system generated the alert (EDR, SIEM, IDS/IPS, firewall, user report) - **Timestamp**: When the event occurred and when it was detected (dwell time gap) - **Affected assets**: Hostnames, IP addresses, user accounts involved - **Alert fidelity**: Historical true-positive rate for this detection rule - **Raw evidence**: Log entries, packet captures, process execution chains ``` Example SIEM alert context: Source: CrowdStrike Falcon Detection: Suspicious PowerShell Execution (T1059.001) Host: WORKSTATION-FIN-042 User: [email protected] Timestamp: 2025-11-15T14:23:17Z Severity: High (detection rule confidence: 92%) Process: powershell.exe -enc SQBFAFgAIAAoAE4AZQB3AC0ATwBiAGoA... Parent: outlook.exe (PID 4812) ``` ### Step 2: Classify the Incident Type Map the alert to a standard incident category per NIST SP 800-61r3: | Category | Examples | |----------|----------| | Unauthorized Access | Compromised credentials, privilege escalation, IDOR | | Denial of Service | Volumetric DDoS, application-layer flood, resource exhaustion | | Malicious Code | Malware execution, ransomware detonation, cryptominer | | Improper Usage | Policy violation, insider data exfiltration, shadow IT | | Reconnaissance | Port scanning, directory enumeration, credential spraying | | Web Application Attack | SQL injection, XSS, SSRF exploitation | ### Step 3: Assign Severity Using Impact Matrix Calculate severity by combining asset criticality with threat severity: ``` Severity = f(Asset Criticality, Threat Type, Data Sensitivity, Lateral Movement Potential) Critical (P1): Crown jewel systems compromised, active data exfiltration, ransomware spreading High (P2): Production system compromise, confirmed malware execution, privileged account takeover Medium (P3): Non-production compromise, unsuccessful exploitation attempt, single endpoint malware Low (P4): Reconnaissance activity, policy violation, benign true positive ``` Response SLA targets: - P1: Acknowledge within 15 minutes, containment within 1 hour - P2: Acknowledge within 30 minutes, containment within 4 hours - P3: Acknowledge within 2 hours, investigation within 24 hours - P4: Acknowledge within 8 hours, investigation within 72 hours ### Step 4: Perform Initial Enrichment Before escalation, enrich the alert with contextual data: - **Threat intelligence**: Check IOCs (IP, hash, domain) against TI platforms (VirusTotal, OTX, MISP) - **Asset context**: Query CMDB for asset owner, business function, data classification - **User context**: Check identity provider for recent authentication anomalies, MFA status - **Historical correlation**: Search for related alerts on the same host/user in the past 30 days - **Network context**: Verify if source/destination IPs are internal, known partners, or external threat actors ### Step 5: Document and Escalate Create a structured triage record and route to the appropriate response tier: ``` Incident Triage Record ━━━━━━━━━━━━━━━━━━━━━ Ticket ID: INC-2025-1547 Triage Analyst: [analyst name] Triage Time: 2025-11-15T14:35:00Z (12 min from alert) Classification: Malicious Code - Macro-based initial access Severity: P2 - High Affected Assets: WORKSTATION-FIN-042 (Finance dept, handles PII) Affected Users: [email protected] IOCs Identified: powershell.exe spawned by outlook.exe, encoded command TI Matches: Base64 payload matches known Qakbot loader pattern Escalation: Tier 2 - Malware IR team Recommended: Isolate endpoint, preserve memory dump, block sender domain ``` ### Step 6: Initiate Containment Hold If severity is P1 or P2, initiate immediate containment actions while awaiting full investigation: - Network-isolate the affected endpoint via EDR (CrowdStrike contain, Defender isolate) - Disable compromised user accounts in Active Directory or identity provider - Block identified malicious IPs/domains at firewall and DNS sinkhole - Preserve volatile evidence (memory dump) before a
Trust audit
CAUTIONgrade B · trust 89/100 Install with care. The audit found things worth knowing before you trust its output.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | WARN |
| L2 | Instruction surface (what it tells the agent) | FAIL |
| L3 | Class-specific surface | PASS |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- none-observed
- Network
- declared (2 observation(s))
- Shell
- none-observed
- Dependencies
- pinned
- Secrets in source
- none-found
Findings (3)
| Unauthorized Access | Compromised credentials, privilege escalation, IDOR |
"criteria": "Crown jewel compromise, active exfiltration, ransomware spreading"},
| Unauthorized Access | Credential compromise, privilege escalation |
Gates applied: no_behavioural_pass.
6c59587be632full audit observations/trust-audit/skill/mukul975__triaging-security-incident.json · Report an issue / request a re-scanAudit history
Every audit this skill has had.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-07 | 6c59587be632 | CAUTION | B | 89 | first audit |
Questions
What does the Triaging Security Incident skill do?
817 structured cybersecurity skills for AI agents · Mapped to 6 frameworks: MITRE ATT&CK, NIST CSF 2.0, MITRE ATLAS, D3FEND, NIST AI RMF & MITRE F3 (Fight Fraud) · agentskills.io standard · Works with Claude Code, GitHub Copilot, Codex CLI, Cursor, Gemini CLI & 20+ platforms · 29 security domains ·
Is Triaging Security Incident safe to install?
With care. The audit graded it B (89/100) and found 3 things worth knowing before you trust this skill, listed below with the exact line each was found on.
What can Triaging Security Incident access on my machine?
The audit observed that it reaches the network. Each of those is consistent with what it says it does. Secrets in the source: none found.
How current is this page?
The grade is for one exact copy of the source (6c59587be632), read on 2026-10-07. The repository is watched, and a new audit runs when it changes — this is the first audit.