What problem does it solve? Security and SOC analysts face alert fatigue, unclear prioritization, and inconsistent investigation quality. This Skill provides a principles-first mindset and structured approach for triaging alerts, reconstructing attack timelines, and communicating findings effectively. ## Core Features & Use Cases - Triage & Prioritization: Classify alerts as true positive, false positive, benign positive, or unknown, and prioritize by business impact using a CRITICAL-to-LOW matrix. - Hypothesis-Driven Investigation: Structure investigations around hypotheses, map attacker behavior to Cyber Kill Chain and MITRE ATT&CK phases, and extract IoCs for hunting and blocking. - Communication & Escalation: Apply audience-appropriate language guidelines for technical teams versus management, with clear escalation thresholds and blameless post-mortem practices. - Use Case: An analyst receives 50 SIEM alerts overnight. Use this Skill to triage by impact, form hypotheses for the top alerts, correlate EDR and network logs, build a timeline, and escalate a confirmed brute-force attempt with concrete IoCs. ## Quick Start Help me triage these SIEM alerts and build an investigation plan for the suspicious login activity.