What problem does it solve? After completing a security investigation, analysts must manually consolidate findings scattered across SIEM, SOAR, threat intelligence, and identity tools into a coherent report for stakeholders and post-incident review, which is time-consuming and error-prone. ## Core Features & Use Cases - Case Context Aggregation: Retrieves full SOAR case details, alerts, comments, and entities, then synthesizes findings from tools like Chronicle SIEM, Google Threat Intelligence, SCC, Okta, and CrowdStrike. - Structured Report Generation: Produces a Markdown report following standard templates with executive summary, timeline, entity enrichment, root cause analysis, and recommendations, plus a Mermaid sequence diagram of the actual investigation workflow. - Delivery & Documentation: Writes the report file, attempts SOAR case attachment with a comment fallback, and optionally uploads to Google Drive or GCS after analyst review and redaction of sensitive data. - Use Case: After triaging a phishing incident in a SOAR case, an analyst invokes this runbook to compile all enrichment findings into a redacted executive-ready report attached directly to the case. ## Quick Start Generate an investigation report for SOAR case 4821 summarizing all findings and attach it to the case.