What problem does it solve? Security analysts handling anomalous login cases must manually pivot across multiple platformsāSOAR, SIEM, threat intelligence, and identity providersāto gather context, decide on a disposition, and take containment action. This Skill orchestrates that entire investigation workflow so evidence is gathered consistently and decisions are documented. ## Core Features & Use Cases - Entity Extraction & Enrichment: Pulls alerts from a SOAR case, identifies entities (users, IPs, hosts), and enriches each with Chronicle SIEM lookups, Google Threat Intelligence reports, and UDM event searches. - Identity Verification & Response: Looks up the primary user in Okta, analyzes suspicious characteristics, andāafter analyst confirmationādisables the compromised account. - Case Documentation: Posts a full investigation summary as a SOAR case comment, including related open cases found via entity-based case search. - Use Case: Given a case of anomalous login alerts, the agent enriches every involved entity with GTI and SIEM context, checks the user's Okta profile for suspicious signals, disables the user upon confirmation, and records findings for Tier 2 escalation or benign closure. ## Quick Start Investigate SOAR case 4821 for anomalous logins by enriching all entities with GTI and SIEM, checking the user's Okta profile, and disabling the account if suspicious.