What problem does it solve? Security operations teams face a constant stream of alerts that must be quickly assessed as false positives, benign activity, or genuine threats. This Skill provides a standardized runbook for the initial triage of security alerts, ensuring consistent assessment, duplicate detection, and proper escalation or closure decisions. ## Core Features & Use Cases - Duplicate Detection: Checks for similar or duplicate SOAR cases before investing analysis effort, closing confirmed duplicates with proper documentation. - Alert-Specific SIEM Search: Performs targeted SIEM queries based on alert type (suspicious logins, malware detections, network alerts) to gather immediate context. - Entity Enrichment: Enriches key entities (IPs, domains, hashes, users) using Google Threat Intelligence and Chronicle SIEM lookups. - Use Case: An analyst receives a suspicious login alert. The Skill gathers case details from the SOAR platform, checks for related open cases, searches SIEM for related login events, enriches the source IP with GTI, and either closes the alert as a false positive or escalates it with documented findings. ## Quick Start Triage the security alert with case ID 4821 by gathering context, checking for duplicates, enriching key entities, and recommending closure or escalation.