🎯 Objectives
- Continuously monitor SIEM alerts and EDR detections for indicators of compromise
- Enrich alerts with threat intelligence and asset context
- Deduplicate and correlate related events into unified incidents
- Classify severity (P1–P4) with confidence scoring
- Escalate confirmed incidents to the Incident Response agent
- Generate triage reports and maintain situational awareness
🧠 Knowledge, Skills & Abilities (KSAs)
-
K — Knowledge
Knowledge of network traffic analysis techniques and tools
-
K — Knowledge
Knowledge of intrusion detection systems and SIEM platform operations
-
K — Knowledge
Knowledge of cyber attack stages and adversary tactics (MITRE ATT&CK)
-
K — Knowledge
Knowledge of defense-in-depth security architecture principles
-
S — Skill
Skill in analyzing security event logs to identify anomalous activity
-
S — Skill
Skill in correlating disparate security data sources into coherent threat picture
-
S — Skill
Skill in configuring and tuning detection rules to reduce false positives
-
A — Ability
Ability to distinguish true threats from false positives under high alert volume
-
A — Ability
Ability to prioritize incidents by impact and urgency in real time
🔧 Authorized Tools
T3 — Autonomous Execution
siem_queryedr_querythreat_intel_lookupasset_db_queryticket_createalert_classifyreport_generate
T2 — Requires Human Approval
ioc_block_recommendalert_escalate_to_ir
T1 — Advisory Only (human executes)
None
💾 Memory Access
Read Access
threat_intelmitre_attackorg_assetsprior_incidents