What it does. Classifies and prioritizes security incidents using structured IR Part of mukul975/Anthropic-Cybersecurity-Skills (817 security skills) (mukul975/Anthropic-Cybersecurity-Skills).
Install
npx skills add mukul975/Anthropic-Cybersecurity-Skills --skill triaging-security-incident-with-ir-playbook, or copy the skill folder into ~/.claude/skills/triaging-security-incident-with-ir-playbook/.
- Raw file:
curl -sL https://raw.githubusercontent.com/mukul975/Anthropic-Cybersecurity-Skills/HEAD/skills/triaging-security-incident-with-ir-playbook/SKILL.md
SKILL.md (verbatim)
2 placeholder credentials were shortened (for example to api_key=YOUR_KEY) to pass the site's secret filter.
name: triaging-security-incident-with-ir-playbook
description: Classifies and prioritizes security incidents using structured IR
playbooks and SIEM/case-management queries (Splunk, TheHive) to determine severity,
assign response teams, and initiate the appropriate response procedures. Use when
a new SOC alert needs triage, multiple concurrent incidents require prioritization,
or automated triage rules need validation or tuning.
domain: cybersecurity
subdomain: incident-response
tags:
- incident-response
- triage
- playbook
- severity-classification
- soc
mitre_attack:
- T1486
- T1490
- T1070
- T1078
version: '1.0'
author: mahipal
license: Apache-2.0
nist_csf:
- RS.MA-01
- RS.MA-02
- RS.AN-03
- RC.RP-01
Triaging Security Incidents with IR Playbooks
When to Use
- New security alert received from SIEM, EDR, or other detection sources
- SOC analyst needs to determine if an alert is a true positive requiring response
- Incident needs severity classification and team assignment
- Multiple concurrent incidents require prioritization
- Automated triage rules need validation or tuning
Prerequisites
- SIEM platform with alert correlation (Splunk, Elastic, QRadar, Sentinel)
- Incident response playbook library (by incident type)
- Severity classification matrix approved by CISO
- On-call rotation and escalation procedures
- Ticketing system for incident tracking (ServiceNow, Jira, TheHive)
- Threat intelligence feeds for IOC enrichment
Workflow
Step 1: Receive and Acknowledge Alert
# Query Splunk for new critical/high severity alerts
index=notable status=new severity IN ("critical","high")
| table _time, rule_name, src, dest, severity, description
| sort -_time
# Query TheHive for new cases
curl -s -H "Authorization: Bearer $THEHIVE_API_KEY" \
"https://thehive.local/api/v1/query?name=list-alerts" \
-H "Content-Type: application/json" \
-d '{"query":[{"_name":"listAlert"},{"_name":"filter","_field":"status","_value":"New"}]}'
# Acknowledge alert in SIEM to prevent duplicate triage
curl -X POST "https://splunk.local:8089/services/notable_update" \
-H "Authorization: Bearer $SPLUNK_TOKEN" \
-d "ruleUIDs=$RULE_UID&status=1&comment=Triage+initiated+by+analyst"
Step 2: Enrich Alert Data
# Enrich source IP with VirusTotal
curl -s "https://www.virustotal.com/api/v3/ip_addresses/$SRC_IP" \
-H "x-apikey: YOUR_KEY | jq '.data.attributes.last_analysis_stats'
# Check IP reputation with AbuseIPDB
curl -s "https://api.abuseipdb.com/api/v2/check?ipAddress=$SRC_IP&maxAgeInDays=90" \
-H "Key: $ABUSEIPDB_KEY" -H "Accept: application/json" | jq '.data'
# Enrich file hash with threat intelligence
curl -s "https://www.virustotal.com/api/v3/files/$FILE_HASH" \
-H "x-apikey: YOUR_KEY | jq '.data.attributes.last_analysis_stats'
# Query internal asset database for affected systems
curl -s "https://cmdb.local/api/assets?ip=$DEST_IP" \
-H "Authorization: Bearer $CMDB_TOKEN" | jq '.asset_criticality, .owner, .environment'
Step 3: Classify Incident Type
# Map alert to incident category using playbook lookup
# Categories: Malware, Phishing, Unauthorized Access, Data Exfiltration,
# DoS/DDoS, Insider Threat, Ransomware, Account Compromise, Web Attack
# Check if alert matches known playbook trigger conditions
grep -i "$ALERT_SIGNATURE" /opt/ir/playbooks/trigger_conditions.yaml
# Determine incident type from MITRE ATT&CK technique
curl -s "https://attack.mitre.org/api/techniques/$TECHNIQUE_ID" | jq '.name, .tactic'
Step 4: Assign Severity Level
# Severity matrix factors:
# 1. Asset criticality (Critical/High/Medium/Low)
# 2. Data sensitivity (PII/PHI/PCI/Confidential/Public)
# 3. Number of affected systems
# 4. Active vs historical threat
# 5. Confirmed vs suspected compromise
# Automated severity calculation
python3 -c "
severity_score = 0
# Asset criticality: Critical=4, High=3, Medium=2, Low=1
severity_score += 4 # Critical server
# Data sensitivity: PII/PHI=4, PCI=3, Confidential=2, Public=1
severity_score += 3 # PCI data
# Scope: Enterprise=4, Department=3, Single system=2, Single user=1
severity_score += 2 # Single system
# Threat status: Active=4, Recent=3, Historical=2, Potential=1
severity_score += 4 # Active threat
if severity_score >= 12: print('CRITICAL - P1')
elif severity_score >= 9: print('HIGH - P2')
elif severity_score >= 6: print('MEDIUM - P3')
else: print('LOW - P4')
print(f'Score: {severity_score}/16')
"
Step 5: Select and Initiate Playbook
# Load appropriate playbook based on incident type
cat /opt/ir/playbooks/ransomware_playbook.yaml
cat /opt/ir/playbooks/phishing_playbook.yaml
cat /opt/ir/playbooks/unauthorized_access_playbook.yaml
# Create incident ticket in TheHive
curl -X POST "https://thehive.local/api/v1/case" \
-H "Authorization: Bearer $THEHIVE_API_KEY" \
-H "Content-Type: application/json" \
-d '{
"title": "IR-2024-XXX: [Incident Type] - [Brief Description]",
"description": "Triage summary and initial findings",
"severity": 3,
"tlp": 2,
"pap": 2,
"tags": ["ransomware", "triage-complete"],
"customFields": {
"playbook": {"string": "ransomware_v2"},
"affected_systems": {"integer": 5}
}
}'
Step 6: Assign Response Team
# Check on-call schedule
curl -s "https://pagerduty.com/api/v2/oncalls?schedule_ids[]=$SCHEDULE_ID" \
-H "Authorization: Token token=$PD_TOKEN" | jq '.oncalls[].user.summary'
# Page incident responders based on severity
# P1/Critical: Page IR lead + senior analysts + CISO
# P2/High: Page IR lead + available analysts
# P3/Medium: Assign to next available analyst
# P4/Low: Queue for business hours processing
curl -X POST "https://events.pagerduty.com/v2/enqueue" \
-H "Content-Type: application/json" \
-d '{
"routing_key": "'$PD_ROUTING_KEY'",
"event_action": "trigger",
"payload": {
"summary": "P1 Security Incident: Ransomware detected on PROD-DB-01",
"severity": "critical",
"source": "SIEM-Splunk",
"custom_details": {"incident_id": "IR-2024-042", "playbook": "ransomware_v2"}
}
}'
Step 7: Document Triage Decision and Hand Off
# Update incident ticket with triage summary
curl -X PATCH "https://thehive.local/api/v1/case/$CASE_ID" \
-H "Authorization: Bearer $THEHIVE_API_KEY" \
-H "Content-Type: application/json" \
-d '{
"status": "InProgress",
"customFields": {
"triage_analyst": {"string": "analyst_name"},
"triage_time": {"date": '$(date +%s000)'},
"severity_justification": {"string": "Critical asset + active threat + PCI data"}
}
}'
Key Concepts
| Concept |
Description |
| True Positive |
Alert correctly identifying a real security incident |
| False Positive |
Alert incorrectly flagging benign activity as malicious |
| Severity Classification |
Ranking incident priority based on impact and urgency |
| Playbook Selection |
Choosing the appropriate response procedure based on incident type |
| IOC Enrichment |
Adding context to indicators from threat intelligence sources |
| Escalation Threshold |
Criteria triggering escalation to higher severity or management |
| Triage SLA |
Time target for initial assessment (typically 15-30 min for critical) |
| Tool |
Purpose |
| Splunk/Elastic/QRadar |
SIEM alert correlation and querying |
| TheHive/SIRP |
Incident case management and playbook tracking |
| VirusTotal/AbuseIPDB |
IOC reputation and enrichment |
| PagerDuty/OpsGenie |
On-call management and alerting |
| MITRE ATT&CK |
Technique classification and mapping |
| Cortex XSOAR |
SOAR platform for automated triage workflows |
Common Scenarios
- Brute Force Alert: Multiple failed logins from single IP. Enrich IP reputation, check geo-location, verify if account was compromised, assign P3 if unsuccessful.
- Malware Detection on Endpoint: AV/EDR quarantined malware. Verify quarantine success, check for lateral movement, assign P2 if persistence detected.
- Suspicious Outbound Traffic: Large data transfer to unknown external IP. Check if known cloud service, verify data classification, assign P1 if exfiltration confirmed.
- Phishing Email Reported: User reports suspicious email. Extract IOCs, check if others received it, assign P2 if credentials were entered.
- Privilege Escalation: User gained admin rights unexpectedly. Verify if authorized change, check for exploitation, assign P1 if unauthorized.
- Triage decision document with severity justification
- Incident ticket with assigned playbook and team
- IOC enrichment summary attached to case
- Escalation notification to appropriate stakeholders
- Initial timeline of events from alert data
Other files in this skill
assets/template.md (verbatim)
Incident Triage Report
| Field |
Value |
| Alert ID |
|
| Alert Source |
[SIEM/EDR/IDS/Email Gateway] |
| Alert Name/Rule |
|
| Alert Time |
YYYY-MM-DD HH:MM UTC |
| Triage Analyst |
|
| Triage Start Time |
YYYY-MM-DD HH:MM UTC |
| Triage End Time |
YYYY-MM-DD HH:MM UTC |
Alert Details
| Field |
Value |
| Source IP |
|
| Source Hostname |
|
| Destination IP |
|
| Destination Hostname |
|
| Protocol/Port |
|
| User Account |
|
| File Hash (SHA256) |
|
| Domain/URL |
|
IOC Enrichment Results
IP Reputation
| Source |
Score |
Details |
| VirusTotal |
/100 |
malicious detections |
| AbuseIPDB |
% confidence |
reports |
| Shodan |
|
Open ports/services |
| Internal Intel |
|
Previous incidents |
File Hash Reputation
| Source |
Score |
Details |
| VirusTotal |
/70+ engines |
Family: |
| MalwareBazaar |
|
Tags: |
| Internal IOC DB |
|
|
Domain Reputation
| Source |
Score |
Details |
| VirusTotal |
/100 |
|
| URLScan.io |
|
|
| PassiveTotal |
|
|
Classification
Incident Type
MITRE ATT&CK Mapping
| Tactic |
Technique ID |
Technique Name |
|
|
|
Severity Assessment
Scoring Factors
| Factor |
Rating |
Score |
| Asset Criticality |
[Critical/High/Medium/Low] |
/4 |
| Data Sensitivity |
[PII-PHI/PCI/Confidential/Public] |
/4 |
| Threat Status |
[Active/Confirmed/Attempted/Recon] |
/4 |
| Scope |
[Enterprise/Department/System/User] |
/4 |
| Total |
|
/16 |
Severity Determination
| Field |
Value |
| Severity |
[Critical/High/Medium/Low] |
| Priority |
[P1/P2/P3/P4] |
| Response SLA |
[15 min/30 min/2 hours/24 hours] |
| Justification |
|
Triage Decision
Playbook Assignment
| Field |
Value |
| Selected Playbook |
|
| Playbook Version |
|
| Assigned Team |
|
| Primary Analyst |
|
| Backup Analyst |
|
Initial Actions Taken
Notes
[Additional context, observations, or concerns from triage]
references/api-reference.md (verbatim)
API Reference: Triaging Security Incidents with IR Playbooks
Incident Classification Types
| Type |
Keywords |
Default Severity |
Playbook |
| Malware |
trojan, ransomware, c2, beacon |
High |
malware-infection-playbook |
| Phishing |
credential harvest, BEC, spear-phishing |
Medium |
phishing-response-playbook |
| Data Exfiltration |
DLP, dns tunnel, large upload |
Critical |
data-exfiltration-playbook |
| Unauthorized Access |
brute force, lateral movement |
High |
unauthorized-access-playbook |
| Denial of Service |
DDoS, SYN flood, volumetric |
High |
ddos-response-playbook |
| Insider Threat |
policy violation, terminated user |
High |
insider-threat-playbook |
| Web Attack |
SQLi, XSS, web shell, RCE |
High |
web-attack-playbook |
Severity Matrix
| Context Factor |
Severity Override |
| Crown jewel system affected |
Critical |
| Active exploitation confirmed |
Critical |
| Multiple systems (>5) affected |
High |
| Single system affected |
Medium |
| Reconnaissance only |
Low |
| Minor policy violation |
Informational |
Escalation Paths
| Severity |
Response Time |
Escalation |
| Critical |
15 minutes |
IR Team + CISO + Legal |
| High |
1 hour |
SOC Tier 2 + IR Team |
| Medium |
4 hours |
SOC Tier 2 |
| Low |
24 hours |
SOC Tier 1 |
| Informational |
Next business day |
SOC Tier 1 |
Python Libraries
| Library |
Version |
Purpose |
json |
stdlib |
Alert parsing and report generation |
enum |
stdlib |
Severity level enumeration |
pathlib |
stdlib |
Output directory management |
datetime |
stdlib |
Triage timestamps |
References
references/standards.md (verbatim)
Standards and Framework References - Incident Triage
NIST SP 800-61 Rev. 3 - Incident Triage Alignment
- Detect (DE): Alert analysis and triage
- DE.AE-02: Potentially adverse events are analyzed to better understand associated activities
- DE.AE-03: Information is correlated from multiple sources
- DE.AE-04: The estimated impact and scope of adverse events is understood
- Respond (RS): Incident classification and escalation
- RS.AN-03: Analysis performed to establish awareness of incident scope
- RS.CO-02: Incidents reported consistent with established criteria
SANS PICERL - Identification Phase
- Phase 2 focuses on detecting and validating security events
- Triage determines if an event qualifies as an incident
- Key activities: alert validation, initial scoping, severity assignment
- Triage SLAs: P1 <15 min, P2 <30 min, P3 <1 hour, P4 <4 hours
NIST Severity Classification (SP 800-61 Rev. 2, Table 3-2)
| Category |
Definition |
Examples |
| CAT 1 - Unauthorized Access |
Individual gains access without permission |
Compromised credentials, privilege escalation |
| CAT 2 - Denial of Service |
Disruption of service availability |
DDoS, resource exhaustion |
| CAT 3 - Malicious Code |
Infection by malware |
Virus, worm, trojan, ransomware |
| CAT 4 - Improper Usage |
Violation of acceptable use policy |
Unauthorized software, policy breach |
| CAT 5 - Scans/Probes |
Reconnaissance activity |
Port scans, vulnerability scans |
| CAT 6 - Investigation |
Unconfirmed suspicious activity |
Anomalous behavior under review |
MITRE ATT&CK - Triage Technique Mapping
- Map observed techniques to ATT&CK framework during triage
- Technique identification helps select appropriate playbook
- Tactic identification reveals attacker's current phase
- Reference: https://attack.mitre.org/
FIRST CSIRT Services Framework
US-CERT Federal Incident Reporting Guidelines
references/workflows.md (verbatim)
Incident Triage with IR Playbooks - Detailed Workflow
Triage Decision Tree
Alert Received
|
v
Is alert from trusted/tuned detection rule?
|-- No --> Check rule logic, verify data source --> Potential false positive
|-- Yes --> Continue
|
v
Does alert match known false positive pattern?
|-- Yes --> Document, close as false positive, tune rule
|-- No --> Continue
|
v
Can indicator be enriched with external threat intel?
|-- Yes --> Enrich with VT, AbuseIPDB, OTX --> Add context
|-- No --> Continue with available data
|
v
What is the incident type?
|-- Malware --> Malware playbook
|-- Phishing --> Phishing playbook
|-- Unauthorized Access --> Access compromise playbook
|-- Data Exfiltration --> Data breach playbook
|-- Ransomware --> Ransomware playbook
|-- DoS/DDoS --> Availability playbook
|-- Insider Threat --> Insider playbook
|
v
Assign severity based on:
- Asset criticality x Threat level x Data sensitivity
|
v
Route to appropriate team with playbook
Severity Assignment Matrix
Impact Score (1-4)
| Score |
Asset Criticality |
Examples |
| 4 |
Critical |
Domain controllers, production databases, financial systems |
| 3 |
High |
Email servers, web applications, file servers |
| 2 |
Medium |
Development systems, internal tools |
| 1 |
Low |
Test systems, non-production workstations |
Urgency Score (1-4)
| Score |
Threat Status |
Indicators |
| 4 |
Active exploitation |
Ongoing attack, real-time data loss |
| 3 |
Confirmed compromise |
Evidence of breach, but not active |
| 2 |
Attempted attack |
Blocked attack, no evidence of success |
| 1 |
Reconnaissance |
Scanning, probing, no exploitation attempt |
Final Severity = Impact x Urgency
| Score Range |
Severity |
Response Time |
Escalation |
| 12-16 |
P1 Critical |
Immediate (15 min) |
CISO + IR Lead + Senior Analysts |
| 8-11 |
P2 High |
30 minutes |
IR Lead + Available Analysts |
| 4-7 |
P3 Medium |
2 hours |
Next available analyst |
| 1-3 |
P4 Low |
24 hours (business hours) |
Queued for analyst review |
Playbook Selection Guide
By Alert Source
| Alert Source |
Likely Playbook |
Key Triage Actions |
| EDR - Malware detection |
Malware IR |
Check quarantine status, verify family |
| Email gateway - Phishing |
Phishing IR |
Extract IOCs, check delivery scope |
| SIEM - Authentication anomaly |
Account Compromise |
Verify account, check lateral movement |
| IDS/IPS - Exploit attempt |
Vulnerability Exploitation |
Verify patch status, check success |
| DLP - Data transfer |
Data Exfiltration |
Classify data, verify authorization |
| Cloud - Impossible travel |
Cloud Account Compromise |
Verify user, check API calls |
By MITRE ATT&CK Tactic
| Tactic |
Playbook |
Priority |
| Initial Access (TA0001) |
Perimeter Breach |
P1-P2 |
| Execution (TA0002) |
Malware/Code Execution |
P1-P2 |
| Persistence (TA0003) |
Backdoor/Implant |
P2 |
| Privilege Escalation (TA0004) |
Privilege Escalation |
P1 |
| Defense Evasion (TA0005) |
Security Tool Bypass |
P2 |
| Credential Access (TA0006) |
Credential Theft |
P1-P2 |
| Discovery (TA0007) |
Reconnaissance |
P3 |
| Lateral Movement (TA0008) |
Lateral Movement |
P1 |
| Collection (TA0009) |
Data Staging |
P2 |
| Exfiltration (TA0010) |
Data Breach |
P1 |
| Impact (TA0040) |
Ransomware/Destruction |
P1 |
IOC Enrichment Workflow
Step 1: Automated Enrichment
- Submit IPs to VirusTotal, AbuseIPDB, Shodan
- Submit file hashes to VirusTotal, MalwareBazaar, Hybrid Analysis
- Submit domains to URLScan.io, VirusTotal, PassiveTotal
- Check against internal IOC database and watchlists
Step 2: Context Addition
- Look up asset in CMDB for criticality and owner
- Check user in HR system for role and access level
- Verify network zone and data classification
- Cross-reference with recent threat intelligence reports
Step 3: Correlation
- Search SIEM for related alerts in past 72 hours
- Check if same IOCs appeared in other incidents
- Correlate with ongoing threat campaigns
- Verify if alert is part of a larger attack chain
Triage Documentation Requirements
- Alert details (source, time, raw data)
- Enrichment results (reputation scores, intelligence hits)
- Classification decision (incident type, severity, justification)
- Selected playbook and version
- Assigned team/analyst
- Initial timeline of observed events
- Known affected assets and accounts
Back to mukul975/Anthropic-Cybersecurity-Skills (817 security skills) or Agent skills.