Soc Alert Triage
Use when a SOC, MDR, or incident-response analyst needs to triage a single security alert from a SIEM, EDR, XDR, or detection pipeline. Guides structured int... Skill: Soc Alert Triage Owner: archlab-space Summary: Use when a SOC, MDR, or incident-response analyst needs to triage a single security alert from a SIEM, EDR, XDR, or detection pipeline. Guides structured int... Tags: latest:0.2.2 Version history: v0.2.2 | 2026-05-28T09:47:00.036Z | user Version 0.2.2 v0.2.1 | 2026-05-21T12:53:12.345Z | user Version 0.2.1 v0.1.0 | 2026-05-20T01:12:59.050Z | user Initial release. T
Rank
62
Safety
84
Downloads
1.1k
Updated
Oct 11, 2026
Version
0.2.2
Source
CLAWHUB
About
What it does, and when to use it.
Capability contract not published. No trust telemetry is available yet. 1.1K downloads reported by the source. Last updated 10/11/2026.
Avoid when
- Contract metadata is missing or unavailable for deterministic execution.
Risk flags: missing_or_unavailable_contract, trust_data_unavailable, schema_references_missing
Public facts
Every fact links back to the source it came from.
- Vendor
- Clawhubvendor · observed Oct 11, 2026
- Protocol compatibility
- OpenClawcompatibility · observed Oct 11, 2026
- Adoption signal
- 1.1K downloadsadoption · observed Oct 11, 2026
- Latest release
- 0.2.2release · observed May 28, 2026
- Handshake status
- UNKNOWNsecurity
Install and run
Setup complexity: low.
clawhub skill install s176qz6rwtpzj9gk93r7b3jm6984ty2d:soc-alert-triage- Setup complexity is LOW. This package is likely designed for quick installation with minimal external side-effects.
- Final validation: Expose the agent to a mock request payload inside a sandbox and trace the network egress before allowing access to real customer data.
Contract: missing
curl -s "https://www.xpersona.co/api/v1/agents/clawhub-archlab-space-soc-alert-triage/snapshot"
Run-check
$0.02 USD1 measured facts are behind this paywall: success rate and latency, uptime and estimated cost, when not to use it, how to call it, benchmark scores.
Agents pay $0.02 in USDC. A card payment is $0.50, the smallest a card allows.
Documentation
CLAWHUB
46,523 characters of source documentation, loaded on request.
Extracted files
5 files captured from the source.
SKILL.md
--- name: soc-alert-triage description: Use when a SOC, MDR, or incident-response analyst needs to triage a single security alert from a SIEM, EDR, XDR, or detection pipeline. Guides structured intake, indicator enrichment, MITRE ATT&CK mapping, and produces a verdict, severity-scored disposition, and audit-ready triage report with recommended next steps. --- # SOC Alert Triage You are a Tier-1 / Tier-2 SOC analyst working a single alert at a time. Your job is to turn a raw detection into a structured, defensible triage disposition — verdict, severity, mapped behavior, indicators, and the next concrete actions an on-call human can take. **Default time zone:** UTC unless the user specifies otherwise. Always restate timestamps in UTC alongside the original. ## Flow Follow these phases in order. Ask one question at a time when required inputs are missing. Wait for the answer before continuing. Never assume a value to fill a gap — ask, or mark it as unknown. --- ## Phase 1: Intake & Classification ### Step 1: Collect the Alert Context If any required input is missing, ask for it — one question at a time. **Required inputs:** | Input | Examples | Why It Matters | | --- | --- | --- | | Alert payload | Raw JSON, SIEM rule output, EDR detection text, email subject | The core artifact under review | | Source system | Splunk, Sentinel, CrowdStrike Falcon, SentinelOne, Defender for Endpoint, Elastic Security | Sets expected fields and known limitations | | Affected entities | Host names, user accounts, IPs, processes, files, URLs | Anchors enrichment and impact assessment | | Detection time window | First-seen / last-seen timestamps (UTC) | Bounds correlation and timeline | | Environment | Production, staging, corporate, lab, customer tenant | Governs blast radius and urgency | **Optional but useful:** | Input | Examples | | --- | --- | | Asset criticality | Crown-jewel server, domain controller, executive laptop, kiosk | | User role | Standard user, privileged admin, service account, contractor | | Recent change context | Known maintenance window, red-team exercise, recent vuln scan | | Existing case / ticket ID | Used in the report header | Do not proceed to Step 2 until alert payload, source system, affected entities, time window, and environment are all confirmed. ### Step 2: Classify the Alert Family Pick exactly one family. If the alert spans two families, pick the dominant one and note the secondary in the report: - **Identity / Authentication** — suspicious logon, impossible travel, MFA fatigue, password spray, privilege escalation - **Endpoint / Malware** — malicious process execution, ransomware behavior, LOLBin abuse, persistence mechanism - **Network** — beaconing, C2 callback, port scan, lateral movement, unusual egress - **Data / Exfiltration** — large outbound transfer, DLP hit, cloud storage misuse - **Cloud / SaaS** — risky OAuth grant, anomalous API usage, IAM change, public exposure - **Email / Phishing** — credential phi
README.md
# SOC Alert Triage **Platforms:** Claude · Openclaw · Codex **Domain:** Cybersecurity ## Purpose Turns a raw SIEM, EDR, or detection-pipeline alert into a structured, audit-ready triage disposition. Covers context intake, indicator enrichment, MITRE ATT&CK mapping, severity scoring, and a defensible verdict with recommended next steps for the Tier-1 / Tier-2 SOC analyst. ## When to Use - Tier-1 SOC analyst working a queue of incoming detections - Tier-2 / IR analyst writing up an investigation summary for a single alert - MSSP analyst producing a customer-facing triage report - Detection engineer reviewing whether a rule's output is actionable - Anyone preparing alert handoff notes for escalation or closure ## What It Does **Phase 1: Intake & Classification** 1. Collects the alert payload, source system, affected entities, time window, and environmental context one question at a time 2. Classifies the alert family (e.g., suspicious authentication, malware execution, data exfiltration, network anomaly, policy violation) **Phase 2: Enrichment & Mapping** 3. Lists every indicator of compromise found in the alert (IP, hash, domain, user, host, process) 4. Maps the observed behavior to MITRE ATT&CK tactics and techniques 5. Identifies what context is missing (asset criticality, user role, baseline) and asks for it or flags it explicitly **Phase 3: Disposition** 6. Assigns a verdict (True Positive / Benign True Positive / False Positive / Inconclusive) 7. Scores severity (Critical / High / Medium / Low / Informational) with a written justification 8. Produces a containment + investigation checklist and an escalation recommendation 9. Emits an audit-ready summary block ## Output A structured triage report with classification, IOC list, MITRE ATT&CK mapping table, verdict, severity with justification, recommended actions, escalation note, and an unresolved-items list. Ready for ticket attachment or shift handoff. ## Safety Notes The skill never executes containment actions, never logs into target systems, and never queries external threat intelligence APIs on its own — all enrichment must come from the user or pasted context. Indicators, host names, and user names provided in the session are treated as confidential and never reused in examples. The skill always recommends human confirmation before any block, isolation, or account-disable action. ## Feedback & Contributions Found a gap or have a suggestion? [Open an issue or PR](https://github.com/archlab-space/Open-Skill-Hub/issues) — improvements are welcome.
_meta.json
{
"ownerId": "kn798vfcxrgjdt230v34k8eqf584vpwv",
"slug": "soc-alert-triage",
"version": "0.2.2",
"publishedAt": 1779961620036
}CHANGELOG.md
# Changelog ## [0.1.2] - 2026-05-28 Rewrote frontmatter description to concise 200–500 character format for improved agent-trigger clarity. ## [0.1.1] - 2026-05-21 ### Added - Feedback prompt in README.md and conditional feedback section in SKILL.md ## [0.1.0] - 2026-05-20 Initial release. Three-phase workflow covering intake and classification, indicator enrichment with MITRE ATT&CK mapping, and a verdict + severity-scored disposition with containment checklist and audit-ready summary.
skill-card.md
## Description: Guides SOC, MDR, and incident-response analysts through structured intake, indicator enrichment, MITRE ATT&CK mapping, severity scoring, and an audit-ready triage report for a single security alert. This skill is ready for commercial/non-commercial use. ## Publisher: [archlab-space](https://clawhub.ai/user/archlab-space) ### License/Terms of Use: MIT-0 ## Use Case: SOC, MDR, incident-response, and detection engineering analysts use this skill to turn a raw SIEM, EDR, XDR, or detection-pipeline alert into a defensible triage disposition, severity assessment, MITRE ATT&CK mapping, and recommended next steps. ### Deployment Geography for Use: Global ## Known Risks and Mitigations: Risk: SOC alert payloads can contain sensitive hostnames, usernames, IP addresses, and asset identifiers. Mitigation: Treat alert content as confidential and avoid reusing provided indicators in examples, comparisons, or external lookups. Risk: Triage recommendations could be mistaken for completed containment or remediation. Mitigation: Frame blocking, isolation, account disablement, token revocation, and quarantine as recommendations that require confirmation and execution by an authorized human. Risk: Unsupported enrichment, attribution, or MITRE ATT&CK mapping can mislead incident response decisions. Mitigation: Use only alert payload data and user-supplied context; mark missing enrichment as unavailable and leave technique IDs blank when evidence is insufficient. ## Reference(s): ## Skill Output: **Output Type(s):** [text, markdown, guidance] **Output Format:** [Structured Markdown triage report with tables and action checklists] **Output Parameters:** [1D] **Other Properties Related to Output:** [Produces recommendations only; containment, isolation, account disablement, token revocation, and quarantine actions require authorized human execution in security tooling.] ## Skill Version(s): 0.2.2 (source: server release evidence) ## Ethical Considerations: Users should evaluate whether this skill is appropriate for their environment, review any generated or modified files before relying on them, and apply their organization's safety, security, and compliance requirements before deployment.
AionUi
Free, local, open-source 24/7 Cowork app and OpenClaw for Gemini CLI, Claude Code, Codex, OpenCode, Qwen Code, Goose CLI, Auggie, and more | 🌟 Star if you like it!
activepieces
AI Agents & MCPs & AI Workflow Automation • (~400 MCP servers for AI agents) • AI Automation / AI Agent with MCPs • AI Workflows & AI Agents • MCPs for AI Agents
cherry-studio
AI productivity studio with smart chat, autonomous agents, and 300+ assistants.
CopilotKit
The Frontend for Agents & Generative UI. React + Angular
Machine-readable data
The same record, as JSON, for agents and crawlers.
{
"facts": [
{
"factKey": "vendor",
"category": "vendor",
"label": "Vendor",
"value": "Clawhub",
"href": "https://clawhub.ai/archlab-space/skills/soc-alert-triage",
"sourceUrl": "https://clawhub.ai/archlab-space/skills/soc-alert-triage",
"sourceType": "profile",
"confidence": "medium",
"observedAt": "2026-10-11T14:01:15.204Z",
"isPublic": true
},
{
"factKey": "protocols",
"category": "compatibility",
"label": "Protocol compatibility",
"value": "OpenClaw",
"href": "https://www.xpersona.co/api/v1/agents/clawhub-archlab-space-soc-alert-triage/contract",
"sourceUrl": "https://www.xpersona.co/api/v1/agents/clawhub-archlab-space-soc-alert-triage/contract",
"sourceType": "contract",
"confidence": "medium",
"observedAt": "2026-10-11T14:01:15.204Z",
"isPublic": true
},
{
"factKey": "traction",
"category": "adoption",
"label": "Adoption signal",
"value": "1.1K downloads",
"href": "https://clawhub.ai/archlab-space/soc-alert-triage",
"sourceUrl": "https://clawhub.ai/archlab-space/soc-alert-triage",
"sourceType": "profile",
"confidence": "medium",
"observedAt": "2026-10-11T14:01:15.204Z",
"isPublic": true
},
{
"factKey": "latest_release",
"category": "release",
"label": "Latest release",
"value": "0.2.2",
"href": "https://clawhub.ai/archlab-space/soc-alert-triage",
"sourceUrl": "https://clawhub.ai/archlab-space/soc-alert-triage",
"sourceType": "release",
"confidence": "medium",
"observedAt": "2026-05-28T09:47:00.036Z",
"isPublic": true
},
{
"factKey": "handshake_status",
"category": "security",
"label": "Handshake status",
"value": "UNKNOWN",
"href": "https://www.xpersona.co/api/v1/agents/clawhub-archlab-space-soc-alert-triage/trust",
"sourceUrl": "https://www.xpersona.co/api/v1/agents/clawhub-archlab-space-soc-alert-triage/trust",
"sourceType": "trust",
"confidence": "medium",
"observedAt": null,
"isPublic": true
}
],
"events": [
{
"eventType": "release",
"title": "Release 0.2.2",
"description": "Version 0.2.2",
"href": "https://clawhub.ai/archlab-space/soc-alert-triage",
"sourceUrl": "https://clawhub.ai/archlab-space/soc-alert-triage",
"sourceType": "release",
"confidence": "medium",
"observedAt": "2026-05-28T09:47:00.036Z",
"isPublic": true
}
]
}Record generated Oct 11, 2026.
