zins-investigate-security-incident

Correlate Zscaler Z-Insights security data sources into a structured incident timeline.

44|24|Updated May 29, 2025
One-click install
npx skills add https://github.com/zscaler/zscaler-mcp-server --skill zins-investigate-security-incident
Or copy as Structured Prompt for Agent▼
Please help me install this Agent Skill.
Skill: zins-investigate-security-incident
Source: https://github.com/zscaler/zscaler-mcp-server/tree/main/skills/zins/investigate-security-incident
Command: npx skills add https://github.com/zscaler/zscaler-mcp-server --skill zins-investigate-security-incident

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

Correlates multiple security data sources to provide a coherent timeline and context for security incidents, accelerating detection, investigation, and response.

Core Features & Use Cases

  • Correlates threat analytics, cyber incidents, firewall actions, web traffic patterns, and shadow IT findings to produce a unified incident timeline.
  • Guides incident responders through evidence gathering, trend analysis, and containment decisions.
  • Use Case: When a security analyst needs to investigate a detected threat, assess incident scope, and understand data exfiltration or shadow IT involvement.

Quick Start

Use the zins-investigate-security-incident skill to generate a complete incident timeline for a specified security alert.

Frequently Asked Questions about zins-investigate-security-incident

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I build a security incident timeline from multiple data sources?▼

To build a security incident timeline, you correlate threat analytics, cyber incidents, firewall actions, web traffic patterns, and shadow IT findings to produce a unified, chronological incident report for investigation.

What is the best way to investigate shadow IT findings during a security incident?▼

Investigating shadow IT findings involves correlating unauthorized application data with firewall actions and web traffic patterns to assess incident scope and understand potential data exfiltration risks.

Can I analyze firewall actions and web traffic patterns together for threat analysis?▼

Yes, you can analyze firewall actions and web traffic patterns together by correlating these data sources to guide incident responders through evidence gathering, trend analysis, and containment decisions.

Do I need access to threat analytics data to investigate an incident with this approach?▼

Yes, investigating an incident requires access to threat analytics, cyber incidents, firewall, web traffic, and shadow IT data sources to successfully generate a complete incident timeline.

What limitations exist when analyzing incident trends across Zscaler Z-Insights?▼

Analysis is limited to the data available within Zscaler Z-Insights, requiring comprehensive access to threat analytics, firewall, web traffic, and shadow IT sources to produce a complete incident timeline.

When do I need to correlate threat analytics for incident response?▼

You need to correlate threat analytics for incident response when a security analyst detects a threat, requiring a coherent timeline to accelerate detection, investigation, and containment decisions.