triaging-security-incident-with-ir-playbook
mukul975/Anthropic-Cybersecurity-Skills
This playbook guides SOC analysts through the structured triage of security incidents. It ingests alerts from SIEM platforms (Splunk, Elastic), enriches data using threat intelligence (VirusTotal, AbuseIPDB), classifies the incident type, and calculates a severity score based on asset criticality and data sensitivity. It culminates in creating structured incident tickets and notifying the appropriate response teams via paging systems, ensuring a comprehensive and standardized incident response workflow.