What problem does it solve? Security analysts need consistent, documented summaries of alert triage decisions for handover, escalation, and audit purposes, but manually compiling case details, events, and threat intelligence into a report is repetitive and error-prone. ## Core Features & Use Cases - Automated Data Gathering: Pulls case details, alerts, UDM events, and involved entities from Chronicle SOAR and SIEM using MCP tools. - Entity Enrichment: Enriches IPs, domains, hashes, and URLs with Google Threat Intelligence reports and SIEM context. - Structured Report Output: Produces a Markdown report with case summary, alert details, enrichment findings, event timeline, and an initial assessment, optionally posted back as a SOAR case comment. - Use Case: After triaging a phishing alert group in a SOAR case, generate a timestamped alert report file documenting key entities, GTI verdicts, and the triage conclusion for Tier 2 handover. ## Quick Start Generate an alert investigation summary report for SOAR case 12345 covering alert group identifiers ABC and save it as a Markdown file.