What problem does it solve? Tier 1 SOC analysts face a high volume of suspicious login alerts (impossible travel, untrusted locations, repeated failed logins) and need a consistent, repeatable process to gather context and decide whether to close or escalate each case. ## Core Features & Use Cases - Entity Extraction & Enrichment: Pulls the user ID, source IP, and hostname from SOAR case events, then enriches them via Chronicle SIEM lookups and Google Threat Intelligence IP reports. - Login Pattern Analysis: Runs UDM queries over the last 24-72 hours of authentication events to detect anomalies such as impossible travel or success-after-failure patterns. - Documented Recommendations: Posts a synthesized triage comment with a clear recommendation (close as false positive, escalate to Tier 2, or consider account lockdown) directly into the SOAR case, with an optional Markdown report. - Use Case: An analyst receives an "Impossible Travel" alert for a user; the skill gathers user history, IP reputation, related open cases, and optional Okta account status, then documents an escalation recommendation in the case. ## Quick Start Triage the suspicious login alerts in SOAR case 4821 and document your findings and recommendation in the case.