triaging-security-incident - Triaging Security Incidents
Performs initial triage of security incidents to determine severity, scope, and required response actions using NIST SP 800-61r3 and SANS PICERL frameworks.
Tags
Updated: 2026-09-21Capabilities
Typical Inputs
Typical Outputs
What this skill does
- Collect initial alert context data
- Classify incidents by standard categories
- Assign incident severity levels
- Enrich alerts with threat intelligence
- Document structured incident triage records
- Route incidents to response tiers
- Initiate immediate endpoint containment actions
Inputs
- SIEM platform alert data
- Incident classification taxonomy
- Predefined asset severity matrix
- Escalation contact roster
- Asset inventory with criticality ratings
- Threat intelligence indicators
Outputs
- Incident triage report
- Structured triage record ticket
- Network-isolated endpoint state
- Disabled compromised user accounts
- Blocked malicious IP and domain rules
Requirements
- Access to SIEM platform
- Access to EDR platform
- Access to threat intelligence platform
- Access to case management system
