building-soc-escalation-matrix skill (Anthropic-Cybersecurity-Skills)

From Public Agent Wiki

What it does. Build a structured SOC escalation matrix defining severity tiers, response Part of mukul975/Anthropic-Cybersecurity-Skills (817 security skills) (mukul975/Anthropic-Cybersecurity-Skills).

Upstream mukul975/Anthropic-Cybersecurity-Skills
Skill file skills/building-soc-escalation-matrix/SKILL.md
License Apache-2.0 (skill folder LICENSE)
Author mukul975
Fetched 2026-09-10

Install

  • npx skills add mukul975/Anthropic-Cybersecurity-Skills --skill building-soc-escalation-matrix, or copy the skill folder into ~/.claude/skills/building-soc-escalation-matrix/.
  • Raw file: curl -sL https://raw.githubusercontent.com/mukul975/Anthropic-Cybersecurity-Skills/HEAD/skills/building-soc-escalation-matrix/SKILL.md

SKILL.md (verbatim)

name: building-soc-escalation-matrix
description: Build a structured SOC escalation matrix defining severity tiers, response
  SLAs, tiered escalation paths, and notification procedures for security incidents,
  using context-driven criteria that combine business risk, asset criticality, and
  data sensitivity. Use when designing or revising how a SOC triages and escalates
  incidents across analyst tiers.
domain: cybersecurity
subdomain: soc-operations
tags:
- soc
- escalation
- incident-management
- severity
- sla
- triage
- tiered-soc
version: '1.0'
author: mahipal
license: Apache-2.0
nist_csf:
- DE.CM-01
- DE.AE-02
- RS.MA-01
- DE.AE-06
mitre_attack:
- T1078
- T1071
- T1041

Building SOC Escalation Matrix

Overview

A SOC escalation matrix defines how security incidents move through the organization based on severity, impact, and response requirements. Modern SOCs use context-driven escalation combining business risk, asset criticality, and data sensitivity rather than purely severity-based models. Organizations using AI and automation in their SOC cut detection-and-containment lifecycle to approximately 161 days, an 80-day improvement over the 241-day industry average.

When to Use

  • When deploying or configuring building soc escalation matrix capabilities in your environment
  • When establishing security controls aligned to compliance requirements
  • When building or improving security architecture for this domain
  • When conducting security assessments that require this implementation

Prerequisites

  • Familiarity with soc operations concepts and tools
  • Access to a test or lab environment for safe execution
  • Python 3.8+ with required dependencies installed
  • Appropriate authorization for any testing activities

SOC Tier Structure

Tier 1 - Alert Triage Analyst

  • Monitors SIEM dashboards and alert queues
  • Performs initial alert classification (true/false positive)
  • Handles P3 and P4 incidents to resolution
  • Escalates P1 and P2 incidents to Tier 2 within SLA
  • Documents initial findings in ticketing system

Tier 2 - Incident Analyst

  • Performs deep-dive investigation on escalated incidents
  • Conducts root cause analysis and scoping
  • Executes containment procedures
  • Handles P2 incidents to resolution
  • Escalates P1 incidents to Tier 3 or management

Tier 3 - Senior Analyst / Threat Hunter

  • Handles P1 critical incidents and APT investigations
  • Performs proactive threat hunting
  • Develops detection rules and playbooks
  • Conducts malware reverse engineering
  • Leads incident response for major breaches

Management Escalation

  • SOC Manager: Operational decisions, resource allocation
  • CISO: Business impact decisions, executive communication
  • Legal/PR: Data breach notification, media response
  • External IR: Third-party incident response engagement

Severity Classification

P1 - Critical

Attribute Value
Impact Active data breach, ransomware spreading, critical systems compromised
Business Impact Revenue loss, regulatory exposure, customer data at risk
Initial Response 15 minutes
Escalation to Tier 2 Immediate
Escalation to Management 30 minutes
Resolution Target 4 hours
Communication Every 30 minutes to stakeholders
Examples Active ransomware, confirmed data exfiltration, domain admin compromise

P2 - High

Attribute Value
Impact Confirmed compromise, limited scope, no active exfiltration
Business Impact Potential revenue impact, contained risk
Initial Response 30 minutes
Escalation to Tier 2 30 minutes if unresolved
Escalation to Management 2 hours
Resolution Target 8 hours
Communication Every 2 hours to SOC management
Examples Compromised user account, malware on single endpoint, insider threat indicator

P3 - Medium

Attribute Value
Impact Suspicious activity requiring investigation
Business Impact Low immediate risk
Initial Response 4 hours
Escalation to Tier 2 8 hours if unresolved
Resolution Target 24 hours
Communication Daily status update
Examples Policy violation, failed brute force, suspicious email report

P4 - Low

Attribute Value
Impact Informational alerts, routine security events
Business Impact Minimal
Initial Response 8 hours
Escalation Only if pattern emerges
Resolution Target 72 hours
Communication Weekly summary
Examples Vulnerability scan findings, expired certificates, policy exceptions

Escalation Decision Matrix

                    Asset Criticality
                    Low        Medium      High        Critical
Severity  Low      P4         P4          P3          P3
          Medium   P4         P3          P2          P2
          High     P3         P2          P2          P1
          Critical P2         P1          P1          P1

Context-Driven Escalation Triggers

Automatic Escalation (no analyst decision needed)

Trigger Action
Ransomware detected on any endpoint P1 - Immediate Tier 3 + Management
Domain admin account compromise P1 - Immediate Tier 3 + Management
Active data exfiltration to external IP P1 - Immediate Tier 3 + Management
Critical infrastructure (DC, SCADA) alert P1 - Immediate Tier 2 minimum
Executive account anomaly P2 - Immediate Tier 2
Multiple hosts with same malware P1 - Immediate Tier 2

Time-Based Escalation

Condition Action
P2 unresolved after 4 hours Escalate to Tier 3
P3 unresolved after 12 hours Escalate to Tier 2
Any incident unresolved past SLA Escalate to SOC Manager
P1 unresolved after 2 hours Escalate to CISO

Communication Templates

P1 Initial Notification

SUBJECT: [P1 CRITICAL] Security Incident - {Incident_ID}

Incident Summary:
- Type: {incident_type}
- Affected Systems: {systems}
- Affected Users: {users}
- Current Status: {status}
- Assigned To: {analyst}

Impact Assessment:
- Business Impact: {impact}
- Data at Risk: {data_risk}
- Containment Status: {containment}

Next Actions:
- {action_1}
- {action_2}

Next Update: {time} (30-minute intervals)
Bridge Line: {conference_details}

Escalation Matrix Implementation

SOAR Integration

# XSOAR escalation playbook trigger
trigger:
  condition: incident.severity == "critical" AND incident.asset_criticality == "high"
  action:
    - assign_tier: 3
    - notify: [soc_manager, ciso]
    - create_war_room: true
    - start_bridge: true
    - set_sla: 4h

auto_escalation_rules:
  - name: P2 Time-Based Escalation
    condition: incident.severity == "high" AND incident.age > 4h AND incident.status != "resolved"
    action:
      - escalate_tier: 3
      - notify: soc_manager
      - add_comment: "Auto-escalated due to SLA breach"

References

Other files in this skill

assets/template.md (verbatim)

SOC Escalation Matrix Template

Priority Definitions

Priority Response SLA Resolution SLA Assigned Tier Mgmt Notification
P1 - Critical 15 min 4 hours Tier 3 30 min
P2 - High 30 min 8 hours Tier 2 2 hours
P3 - Medium 4 hours 24 hours Tier 1 As needed
P4 - Low 8 hours 72 hours Tier 1 Weekly

Escalation Contacts

Role Name Phone Email Availability
Tier 1 Lead 24/7
Tier 2 Lead 24/7
Tier 3 Lead On-call
SOC Manager Business hours + on-call
CISO On-call for P1

Auto-Escalation Rules

Trigger Priority Action
Ransomware detected P1 Tier 3 + CISO
Domain admin compromise P1 Tier 3 + CISO
Active data exfiltration P1 Tier 3 + CISO
Executive account anomaly P2 Tier 2 + SOC Manager
SLA breach +1 Tier Notify SOC Manager

references/api-reference.md (verbatim)

API Reference: SOC Escalation Matrix

Priority Tiers

Tier Response SLA Update SLA Resolution SLA
P1 Critical 15 min 1 hour 4 hours
P2 High 30 min 2 hours 8 hours
P3 Medium 1 hour 4 hours 24 hours
P4 Low 4 hours 8 hours 72 hours

Alert Categories

Category Default Priority Auto-Escalate Triggers
Malware P2 ransomware, wiper, apt
Phishing P3 executive_target, credential_harvested
Unauthorized Access P2 admin_account, domain_controller
Data Exfiltration P1 pii, financial, classified
Insider Threat P2 privileged_user, data_staging

Escalation Chain

P1: SOC Analyst → SOC Lead → IR Manager → CISO
P2: SOC Analyst → SOC Lead → IR Manager
P3: SOC Analyst → SOC Lead
P4: SOC Analyst

Notification Channels

Tier Channels
P1 Slack #critical-alerts, PagerDuty, Email CISO, SMS
P2 Slack #soc-alerts, PagerDuty, Email IR Manager
P3 Slack #soc-alerts, Email SOC Lead
P4 Slack #soc-triage

PagerDuty Incident API

POST https://events.pagerduty.com/v2/enqueue
{
  "routing_key": "SERVICE_KEY",
  "event_action": "trigger",
  "payload": {
    "summary": "P1 Alert: Data exfiltration detected",
    "severity": "critical",
    "source": "SOC SIEM"
  }
}

Slack Webhook Notification

POST https://hooks.slack.com/services/T.../B.../xxx
{
  "channel": "#critical-alerts",
  "text": "P1 Incident: ..."
}

Auto-Escalation Rules

Condition Action
Response SLA exceeded Escalate to next in chain
>= 3 correlated alerts Increase priority by 1
VIP user affected Auto-escalate to P1
Critical asset impacted Increase priority by 1

references/standards.md (verbatim)

Standards - SOC Escalation Matrix

NIST SP 800-61 Rev 2 Incident Handling

  • Defines incident categories and severity levels
  • Recommends functional impact, information impact, and recoverability as factors
  • Guides escalation based on incident classification

ITIL Incident Management

  • P1-P4 priority classification framework
  • Impact x Urgency = Priority matrix
  • SLA management for each priority level

SOC-CMM (SOC Capability Maturity Model)

  • Level 1: Ad-hoc escalation, no formal process
  • Level 2: Defined escalation paths, documented SLAs
  • Level 3: Automated escalation with SOAR integration
  • Level 4: Context-driven escalation with risk scoring
  • Level 5: AI-assisted prioritization and auto-escalation

Response Time Standards

Priority Industry Standard Best Practice
P1 15 min response, 4h resolution 5 min response, 2h containment
P2 30 min response, 8h resolution 15 min response, 4h containment
P3 4h response, 24h resolution 2h response, 12h resolution
P4 8h response, 72h resolution 4h response, 48h resolution

references/workflows.md (verbatim)

Workflows - SOC Escalation Matrix

Escalation Flow

Alert Generated
    |
    v
Tier 1 Triage (15 min)
    |
    +-- P4/P3: Handle to resolution
    |
    +-- P2: Escalate to Tier 2
    |       |
    |       +-- Resolved: Close
    |       +-- Unresolved (4h): Escalate to Tier 3
    |
    +-- P1: Immediate escalation
            |
            v
        Tier 3 + Management Notified
            |
            v
        War Room / Bridge Activated
            |
            v
        Containment within SLA
            |
            v
        Resolution + Post-Incident Review

Notification Matrix

Priority Tier 1 Tier 2 Tier 3 SOC Mgr CISO Legal
P1 Aware Aware Lead Notified Notified Standby
P2 Aware Lead Consulted Informed - -
P3 Lead Consulted - - - -
P4 Lead - - - - -

Back to mukul975/Anthropic-Cybersecurity-Skills (817 security skills) or Agent skills.