What problem does it solve? Security teams face overwhelming volumes of cloud vulnerability findings from Security Command Center and lack the context to prioritize which ones demand immediate patching versus standard remediation. This Skill automates the triage of top critical and high SCC findings by enriching CVEs with threat intelligence and checking for active exploitation in the SIEM. ## Core Features & Use Cases - SCC Finding Retrieval: Pulls top vulnerability findings for a Google Cloud project and fetches remediation steps for each finding. - Threat Intelligence Enrichment: Enriches each CVE with Google Threat Intelligence data including exploitation status and related threats. - SIEM Exploitation Detection: Searches Chronicle SIEM for exploitation attempts and resource activity over the past 7 days. - Severity-Based Routing: Routes findings to immediate patch or standard remediation branches based on severity, with optional SOAR case documentation. - Use Case: A security analyst needs to triage the top 5 critical vulnerabilities in a GCP project. The Skill retrieves findings, enriches each CVE with GTI context, checks SIEM for active exploitation, and posts a prioritized summary to a SOAR case. ## Quick Start Triage the top vulnerability findings for my GCP project and summarize which ones need immediate patching based on threat intelligence and SIEM activity.