triaging-security-incident-with-ir-playbook - Triaging Security Incidents with IR Playbooks
Classify and prioritize security incidents using structured IR playbooks to determine severity, assign response teams, and initiate response procedures.
Tags
Updated: 2026-09-20Capabilities
Typical Inputs
Typical Outputs
What this skill does
- Acknowledge security alerts
- Enrich alert indicator data
- Classify security incident types
- Calculate incident severity levels
- Initiate incident response playbooks
- Assign incident response teams
- Document triage decisions
Inputs
- Security alert data
- SIEM correlation queries
- Threat intelligence API keys
- IR playbook library
- Asset CMDB database
- On-call schedule data
Outputs
- Triage decision document
- Incident case ticket
- IOC enrichment summary
- Escalation notification
- Initial event timeline
Requirements
- SIEM platform
- TheHive or ticketing system
- VirusTotal and AbuseIPDB API access
- PagerDuty integration
- Python 3 runtime
