{"id":"6fff6f52-401a-48ee-9ec1-8b12c1d5bcea","slug":"clawhub-archlab-space-soc-alert-triage","name":"Soc Alert Triage","description":"Use when a SOC, MDR, or incident-response analyst needs to triage a single security alert from a SIEM, EDR, XDR, or detection pipeline. Guides structured int...","canonicalUrl":"https://www.xpersona.co/agent/clawhub-archlab-space-soc-alert-triage","sourceUrl":"https://clawhub.ai/archlab-space/soc-alert-triage","homepage":"https://clawhub.ai/archlab-space/skills/soc-alert-triage","source":"CLAWHUB","vendor":{"slug":"clawhub","label":"Clawhub","url":"https://clawhub.ai/archlab-space/skills/soc-alert-triage"},"protocols":["OPENCLEW"],"capabilities":[],"trustScore":null,"trustConfidence":"unknown","artifactCount":0,"benchmarkCount":0,"lastRelease":"0.2.2","freshnessAt":"2026-10-11T14:01:15.191Z","freshnessLabel":"Oct 11, 2026","securityReviewed":true,"openapiReady":false,"stats":[{"label":"Trust score","value":"Unknown"},{"label":"Compatibility","value":"OpenClaw"},{"label":"Freshness","value":"Oct 11, 2026"},{"label":"Vendor","value":"Clawhub"},{"label":"Artifacts","value":"0"},{"label":"Benchmarks","value":"0"},{"label":"Last release","value":"0.2.2"}],"factsPreview":[{"factKey":"vendor","category":"vendor","label":"Vendor","value":"Clawhub","href":"https://clawhub.ai/archlab-space/skills/soc-alert-triage","sourceUrl":"https://clawhub.ai/archlab-space/skills/soc-alert-triage","sourceType":"profile","confidence":"medium","observedAt":"2026-10-11T14:01:15.204Z","isPublic":true},{"factKey":"protocols","category":"compatibility","label":"Protocol compatibility","value":"OpenClaw","href":"https://www.xpersona.co/api/v1/agents/clawhub-archlab-space-soc-alert-triage/contract","sourceUrl":"https://www.xpersona.co/api/v1/agents/clawhub-archlab-space-soc-alert-triage/contract","sourceType":"contract","confidence":"medium","observedAt":"2026-10-11T14:01:15.204Z","isPublic":true},{"factKey":"traction","category":"adoption","label":"Adoption signal","value":"1.1K downloads","href":"https://clawhub.ai/archlab-space/soc-alert-triage","sourceUrl":"https://clawhub.ai/archlab-space/soc-alert-triage","sourceType":"profile","confidence":"medium","observedAt":"2026-10-11T14:01:15.204Z","isPublic":true},{"factKey":"latest_release","category":"release","label":"Latest release","value":"0.2.2","href":"https://clawhub.ai/archlab-space/soc-alert-triage","sourceUrl":"https://clawhub.ai/archlab-space/soc-alert-triage","sourceType":"release","confidence":"medium","observedAt":"2026-05-28T09:47:00.036Z","isPublic":true},{"factKey":"handshake_status","category":"security","label":"Handshake status","value":"UNKNOWN","href":"https://www.xpersona.co/api/v1/agents/clawhub-archlab-space-soc-alert-triage/trust","sourceUrl":"https://www.xpersona.co/api/v1/agents/clawhub-archlab-space-soc-alert-triage/trust","sourceType":"trust","confidence":"medium","observedAt":null,"isPublic":true}],"highlights":["1.1K downloads","Trust evidence available"],"agentCard":{"name":"Soc Alert Triage","description":"Use when a SOC, MDR, or incident-response analyst needs to triage a single security alert from a SIEM, EDR, XDR, or detection pipeline. Guides structured int...","source":"CLAWHUB","sourceId":"clawhub:s176qz6rwtpzj9gk93r7b3jm6984ty2d:soc-alert-triage","homepage":"https://clawhub.ai/archlab-space/skills/soc-alert-triage","repository":"https://clawhub.ai/archlab-space/soc-alert-triage","documentation":"https://www.xpersona.co/agent/clawhub-archlab-space-soc-alert-triage","protocols":["OPENCLEW"],"examples":[{"kind":"example","language":"text","snippet":"# SOC Alert Triage Report\n**Alert ID / Case:** [if provided]\n**Source:** [source system]\n**Detection window:** [t0–t1 UTC]\n**Environment:** [production / corp / etc.]\n**Triaged:** [today's date, UTC]\n\n---\n\n## Classification\n- **Family:** [Identity / Endpoint / Network / ...]\n- **Secondary family (if any):** [...]\n\n## Verdict\n**[True Positive / Benign True Positive / False Positive / Inconclusive]**\n\n[2–4 sentence justification grounded in the evidence]\n\n## Severity\n**[Critical / High / Medium / Low / Informational]**\n\n[1–2 sentence justification tying severity to asset criticality and verdict]\n\n---\n\n## Indicators of Compromise\n\n| Type | Value | Role in Alert |\n| --- | --- | --- |\n[rows]\n\n## MITRE ATT&CK Mapping\n\n| Behavior Observed | Tactic | Technique (ID) | Evidence Snippet |\n| --- | --- | --- | --- |\n[rows]\n\n---\n\n## Recommended Actions\n\n### Containment (recommend; human must confirm)\n- [...]\n\n### Investigation\n- [...]\n\n### Escalation\n- [Role to escalate to, condition, target SLA]\n\n---\n\n## Missing Context / Open Questions\n- [...]\n\n## Notes\n[Assumptions, data limitations, secondary family, tuning suggestions]"},{"kind":"example","language":"text","snippet":"# SOC Alert Triage Report\n**Alert ID / Case:** [if provided]\n**Source:** [source system]\n**Detection window:** [t0–t1 UTC]\n**Environment:** [production / corp / etc.]\n**Triaged:** [today's date, UTC]\n\n---\n\n## Classification\n- **Family:** [Identity / Endpoint / Network / ...]\n- **Secondary family (if any):** [...]\n\n## Verdict\n**[True Positive / Benign True Positive / False Positive / Inconclusive]**\n\n[2–4 sentence justification grounded in the evidence]\n\n## Severity\n**[Critical / High / Medium / Low / Informational]**\n\n[1–2 sentence justification tying severity to asset criticality and verdict]\n\n---\n\n## Indicators of Compromise\n\n| Type | Value | Role in Alert |\n| --- | --- | --- |\n[rows]\n\n## MITRE ATT&CK Mapping\n\n| Behavior Observed | Tactic | Technique (ID) | Evidence Snippet |\n| --- | --- | --- | --- |\n[rows]\n\n---\n\n## Recommended Actions\n\n### Containment (recommend; human must confirm)\n- [...]\n\n### Investigation\n- [...]\n\n### Escalation\n- [Role to escalate to, condition, target SLA]\n\n---\n\n## Missing Context / Open Questions\n- [...]\n\n## Notes\n[Assumptions, data limitations, secondary family, tuning suggestions]"}]}}