Agent skill

Triaging Security Alerts

by trilwu in trilwu/secskills

Work a security alert queue to a defensible disposition — separating true positives from false positives and benign true positives, reasoning about base rates before escalating, ordering enrichment…

MITAuto-check passedDevOps & Cloud

Install Triaging Security Alerts

skills CLI
$ npx skills add trilwu/secskills --skill triaging-security-alerts -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install trilwu/secskills triaging-security-alerts --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/trilwu/secskills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/secskills-defense/skills/triaging-security-alerts .claude/skills/triaging-security-alerts && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
triaging-security-alerts
GitHub stars
157
Token cost
~2.5k tokens
SKILL.md length
1,402 words
Files
1
Skills in repo
50
Repo updated
First seen
Licence
MIT

At a glance

Work a security alert queue to a defensible disposition — separating true positives from false positives and benign true positives, reasoning about base rates before escalating, ordering enrichment…

  • Works in 5 steps: What is this asset and who uses it? A… → Is this normal for this host or user?… → Was it authorized? Change tickets,… → …
  • Deciding whether an alert warrants incident response
  • SKILL.md covers When to Use, When NOT to Use, Three Dispositions, Not Two and Base Rates Decide More Than…, plus 6 more sections
  • Calls curl; reaches defuddle.md

What it does

Triaging Security Alerts is an agent skill from trilwu/secskills. Work a security alert queue to a defensible disposition — separating true positives from false positives and benign true positives, reasoning about base rates before escalating, ordering enrichment by cheapest discriminator, time-boxing, and documenting negative results so a closed alert is evidence rather than a guess. Use when triaging SOC or EDR alerts, deciding whether an alert warrants incident response, working through an alert backlog, or determining why a detection keeps firing.

Its SKILL.md is about 2.5k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in DevOps & Cloud, covering Incident response and Security operations. The repository describes itself as: Transform Claude Code into your personal security engineer. The licence is MIT.

When your agent uses it

  • Deciding whether an alert warrants incident response
  • Working through an alert backlog
  • Determining why a detection keeps firing

Example prompts

  • “/triaging-security-alerts”

Workflow steps

5 steps, taken from the first numbered list in SKILL.md.

  1. What is this asset and who uses it? A domain controller and a
  2. Is this normal for this host or user? Frequency and history first. An
  3. Was it authorized? Change tickets, maintenance windows, deployment
  4. What is the parent and the chain? Provenance discriminates far better
  5. Only then, external reputation. Hash and IOC lookups are the last

What it can do on your machine

Read from SKILL.md and the folder at commit ca53957. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • curl

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Hosts in commands or code, which the agent is likely to contact:

    • defuddle.md

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Triaging Security Alerts loads about 2.5k tokens when it runs. Until then it costs about 129 tokens; SKILL.md has 1,402 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~129
When it runs · the whole SKILL.md, loaded when a task matches
~2.5k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from trilwu/secskills at commit ca53957, republished under its MIT licence (© trilwu). 1,402 words, ~2,498 tokens.

Download SKILL.mdSave it as .claude/skills/triaging-security-alerts/SKILL.md (or your agent's skills folder).
name
triaging-security-alerts
description
Work a security alert queue to a defensible disposition — separating true positives from false positives and benign true positives, reasoning about base rates before escalating, ordering enrichment by cheapest discriminator, time-boxing, and documenting negative results so a closed alert is evidence rather than a guess. Use when triaging SOC or EDR alerts, deciding whether an alert warrants incident response, working through an alert backlog, or determining why a detection keeps firing.
verified
2026-07-27

Triaging Security Alerts

Triage is the highest-volume work in security and the least written about. The output is a disposition you can defend later — most often to someone asking why an alert that preceded a breach was closed.

Three properties make it hard. The overwhelming majority of alerts are not incidents, so the prior is against you on every single one. The cost of the two error types is wildly asymmetric — a wrongly escalated alert wastes hours, a wrongly closed one costs the breach. And the queue keeps arriving, so unbounded care on one alert is care stolen from the next.

When to Use

  • Working an alert queue from a SIEM, EDR, or cloud security tool
  • Deciding whether an alert becomes an incident
  • Reworking a backlog, or a specific alert that keeps recurring
  • Reviewing another analyst's disposition
  • Determining whether a noisy detection should be tuned or removed

When NOT to Use

  • The alert is already confirmed malicious — stop triaging and use responding-to-incidents; triage ends where response begins
  • Searching for compromise with no alert to start from — use hunting-threats; a hunt is hypothesis-driven, triage is queue-driven
  • Rewriting the rule — use engineering-detections or writing-sigma-rules; feed your triage findings to it rather than tuning in place mid-queue
  • Analysing the sample an alert pointed at — use analyzing-malware
  • Investigating a specific compromised host in depth — use investigating-windows-endpoints or the relevant cloud investigation skill

Three Dispositions, Not Two

The common failure is a binary true/false frame. There are three, and conflating the last two destroys your detection programme:

DispositionMeaningCorrect action
True positiveDetection fired correctly, activity was maliciousEscalate to incident response
Benign true positiveDetection fired correctly, activity was authorizedClose, and record the authorizing context. Do not tune the rule away
False positiveDetection logic was wrong — it did not match what it claims to matchClose, and send it to detection engineering as a logic defect

An admin legitimately dumping LSASS for a memory test is a benign true positive: the rule worked perfectly. Filing it as a false positive leads someone to weaken a rule that is functioning exactly as designed. Over a year that is how a detection programme quietly dies.

Base Rates Decide More Than Evidence Does

Most triage errors are not evidence-reading errors. They are prior-probability errors.

Take a detection that is 99% accurate, firing across 10,000 hosts where 1 is actually compromised. It produces roughly 100 false alerts and 1 true one. A positive alert is about 1% likely to be a real compromise — even at 99% accuracy. This is why "the tool flagged it" carries almost no weight on its own, and why an analyst who escalates on tool severity alone will be wrong almost every time.

The practical consequences:

  • Severity is a property of the rule, not of the alert. It was assigned by whoever wrote the detection, before your environment existed.
  • Ask what else would produce this signal. If routine administration, backup software, or a vulnerability scanner explains it, that explanation is far more likely than compromise before you have contrary evidence.
  • Corroboration beats confidence. Two weak independent signals pointing the same way move the posterior much further than one strong signal, because their benign explanations rarely coincide.
  • Rare things are rare — but rarity is not innocence. The point is to make the prior explicit so evidence has to actually overcome it, not to explain every alert away.

Order Enrichment by Cheapest Discriminator

Work the question that most cheaply splits benign from malicious. Do not run a fixed enrichment checklist.

  1. What is this asset and who uses it? A domain controller and a developer's laptop generate different priors for identical activity.
  2. Is this normal for this host or user? Frequency and history first. An action that ran daily for eight months is a baseline, not an event.
  3. Was it authorized? Change tickets, maintenance windows, deployment pipelines. Most benign true positives resolve here.
  4. What is the parent and the chain? Provenance discriminates far better than the artifact itself. powershell.exe is meaningless; spawned by winword.exe is not.
  5. Only then, external reputation. Hash and IOC lookups are the last cheap step, not the first. A clean reputation proves nothing about targeted activity, and a dirty one still needs the local context above.

Stop as soon as one of these settles it. Running every step on every alert is how the queue wins.

Time-Boxing and Escalation

Set a bound before you start — commonly 15 minutes for a routine alert. When it expires, you must choose, and the choice is not "keep digging":

  • Enough to close → close with the evidence recorded.
  • Enough to escalate → escalate.
  • Neither → escalate anyway. An alert that resists a full time-box is itself a signal. Ambiguity is not a reason to keep it in your queue; it is a reason to give it more resources than you have.

Escalate immediately, without finishing triage, on any of: confirmed execution on a crown-jewel asset, credential access on a domain controller or identity provider, evidence of lateral movement, security tooling being disabled, or anything touching backup infrastructure. These are too expensive to be wrong about slowly.

Show full SKILL.md (548 more words)Show less

A Closed Alert Must Be Evidence

Record what you checked, what you found, and what would change your mind. A disposition with no reasoning is unreviewable, and the alert that preceded a breach is always reviewed.

The dangerous phrasing is "no evidence of compromise found" where the honest statement is "the telemetry that would show compromise is not collected." The first closes the question; the second is a finding about a visibility gap and belongs to engineering-detections.

Every disposition also carries information back to detection engineering: false positives are logic defects, repeated benign true positives are missing authorized-context filters, and a rule producing only noise for months should be measured and removed rather than endured.

Rationalizations to Reject

  • "The tool rated it critical, so it is serious." Severity was set by the rule author against a generic environment. Your base rate is local.
  • "It has fired a hundred times before and always been nothing." Prior benignity is evidence, not proof — and an attacker who knows the rule is ignored will use exactly that technique. Check this instance's specifics.
  • "The user said it was them." Confirms someone used the account, not that the account was not also used by someone else. Compromised users answer the phone. Corroborate against telemetry.
  • "It stopped on its own, so it resolved." Activity ceasing is equally consistent with the operator finishing, moving on, or going quiet. Nothing self-resolves in security.
  • "I could not find anything, so it is a false positive." Absence of evidence in telemetry you did not check, or that is not collected, is not a false positive. Say which you mean.
  • "It is a known false positive." Then it should have been tuned or filtered. If it is still firing, either the tuning is missing or it is actually a benign true positive being mislabelled — both are actions, not dispositions.
  • "I will keep digging until I am certain." Certainty is not on the menu, and the queue is still arriving. Time-box, then escalate on ambiguity.
  • "Escalating something benign makes me look careless." Escalating ambiguity is the system working. Closing ambiguity silently is the failure the post- incident review will find.

Reading External Sources

Fetch public advisories, specifications, and vendor reports as Markdown:

bash
curl -sL "https://defuddle.md/<url>"      # scheme in the path is optional

This strips page boilerplate — roughly 78% fewer tokens on a prose page — and returns the full text rather than a summary, so you can grep it and trust a negative result.

Three things it is not for. Fetch JSON and API responses raw, because readability extraction mangles structured data. Fetch authenticated or JavaScript-rendered pages directly, because it retrieves them anonymously. And never route adversary infrastructure (phishing links, C2, malware hosting), client-owned hosts, or engagement URLs through it — the request leaves your machine to a third party, and for live adversary infrastructure it also tips off the operator.

Some sites block the extractor and return an error blob rather than the page — {"error":"Failed to fetch: 418 I'm a teapot"} from freedesktop.org, for instance. That is the fetch being refused, not the source saying the thing does not exist. Re-fetch the URL directly before drawing any conclusion from it.

References

  • responding-to-incidents — where a true positive goes next
  • engineering-detections — where false positives and tuning gaps go back to
  • hunting-threats — the hypothesis-driven counterpart to queue-driven triage
  • investigating-windows-endpoints — deep host analysis once triage escalates

© trilwu, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in secskills-defense/skills/triaging-security-alerts of trilwu/secskills.

Open the folder on GitHubat commit ca53957

Compare with similar skills

Triaging Security Alerts next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Triaging Security Alerts compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Triaging Security Alerts this skilltrilwu/secskills157—~2.5kAutomated safety check: PassMIT
Implementing Soar Playbook With Palo Alto Xsoarmukul975/Anthropic-Cybersecurity-Skills34k—~2.4kAutomated safety check: PassApache-2.0
Conducting Cloud Incident Responsemukul975/Anthropic-Cybersecurity-Skills34k—~3kAutomated safety check: PassApache-2.0
Performing Soc Tabletop Exercisemukul975/Anthropic-Cybersecurity-Skills34k—~4.2kAutomated safety check: PassApache-2.0
Incident Responsealirezarezvani/claude-skills28k—~3.8kAutomated safety check: PassMIT
Soc Operationsbriiirussell/cybersecurity-skills413—~2.9kAutomated safety check: PassMIT

Similar skills

  • Implementing Soar Playbook With Palo Alto Xsoar

    mukul975/Anthropic-Cybersecurity-Skills

    Build automated incident response playbooks in Cortex XSOAR (Demisto) using its YAML playbook structure, integration commands, and task types to orchestrate phishing, malware, account-compromise…

    34k GitHub stars~2.4k tokensUpdated 1 mo ago
    DevOps & CloudAuto-check passed
  • Conducting Cloud Incident Response

    mukul975/Anthropic-Cybersecurity-Skills

    Respond to security incidents in AWS, Azure, and GCP via identity-based containment, cloud-native log analysis (CloudTrail, Azure Activity Logs, GCP Audit Logs), resource isolation, and forensic…

    34k GitHub stars~3k tokensUpdated 1 mo ago
    DevOps & CloudAuto-check passed
  • Performing Soc Tabletop Exercise

    mukul975/Anthropic-Cybersecurity-Skills

    Performs tabletop exercises for SOC teams simulating security incidents through discussion-based scenarios to test incident response procedures, communication workflows, and decision-making under…

    34k GitHub stars~4.2k tokensUpdated 1 mo ago
    DevOps & CloudAuto-check passed
  • Incident Response

    alirezarezvani/claude-skills

    A skill your agent uses when a security incident has been detected or declared and needs classification, triage, escalation path determination, and forensic evidence collection.

    28k GitHub stars~3.8k tokensUpdated 1 mo ago
    DevOps & CloudAuto-check passed
  • Soc Operations

    briiirussell/cybersecurity-skills

    Build, run, and improve a Security Operations Center — alert prioritization, runbook authoring, escalation criteria, on-call structure, alert tuning workflow, MTTD / MTTR / fidelity KPIs, analyst…

    413 GitHub stars~2.9k tokensUpdated 4 mo ago
    DevOps & CloudAuto-check passed
  • Analyzing Persistence Mechanisms In Linux

    mukul975/Anthropic-Cybersecurity-Skills

    Scan Linux systems for persistence mechanisms including crontab/systemd entries, LDPRELOAD injection, shell profile modifications (.bashrc, .profile), and SSH authorizedkeys backdoors, then…

    34k GitHub stars~801 tokensUpdated 1 mo ago
    DevOps & CloudAuto-check: notes

More from trilwu/secskills

All 50 skills in this repo
  • Audit source code for exploitable vulnerabilities using threat-model-driven review, taint tracing, invariant checking, and variant analysis.

    157 GitHub stars~3.2k tokensUpdated 1 mo ago
    Auto-check passed
  • Perform OSINT, subdomain enumeration, port scanning, web reconnaissance, email harvesting, and cloud asset discovery for initial access.

    157 GitHub stars~3.1k tokensUpdated 1 mo ago
    Auto-check: notes
  • Securing AI Systems

    trilwu/secskills

    Assess and harden LLM applications and agentic systems against prompt injection, tool misuse, excessive agency, memory poisoning, RAG data leakage, and model supply-chain risk, mapped to the OWASP…

    157 GitHub stars~2.9k tokensUpdated 1 mo ago
    Auto-check passed
  • Analyzing Binaries

    trilwu/secskills

    Reverse engineer compiled binaries, firmware, and mobile app packages using triage, static disassembly, decompilation, and dynamic instrumentation.

    157 GitHub stars~2.9k tokensUpdated 1 mo ago
    Auto-check passed
  • Analyzing Go Binaries

    trilwu/secskills

    Reverse engineer Go binaries by recovering function names and types from pclntab and moduledata using GoReSym, redress, and IDA/Ghidra Go plugins, and by reading Go's non-standard calling…

    157 GitHub stars~2k tokensUpdated 1 mo ago
    Auto-check passed
  • Analyzing iOS Binaries

    trilwu/secskills

    Analyze iOS applications at the binary level — decrypting FairPlay-protected IPAs with frida-ios-dump or bagbak, inspecting Mach-O load commands, recovering Objective-C headers with class-dump, and…

    157 GitHub stars~2k tokensUpdated 1 mo ago
    Auto-check passed

Questions about Triaging Security Alerts

What does Triaging Security Alerts do?

Work a security alert queue to a defensible disposition — separating true positives from false positives and benign true positives, reasoning about base rates before escalating, ordering enrichment…. Triaging Security Alerts is an agent skill from trilwu/secskills. Work a security alert queue to a defensible disposition — separating true positives from false positives and benign true positives, reasoning about base rates before escalating, ordering enrichment by cheapest discriminator, time-boxing, and documenting negative results so a closed alert is evidence rather than a guess.

When should I use Triaging Security Alerts?

Triaging Security Alerts fits situations like: deciding whether an alert warrants incident response; working through an alert backlog; determining why a detection keeps firing.

How do I install Triaging Security Alerts in Claude Code?

Run `npx skills add trilwu/secskills --skill triaging-security-alerts -a claude-code`. Or copy the skill folder (secskills-defense/skills/triaging-security-alerts in trilwu/secskills) into .claude/skills/triaging-security-alerts in your project. Claude Code loads it when a task matches its description.

How do I install Triaging Security Alerts in Codex?

Run `npx skills add trilwu/secskills --skill triaging-security-alerts -a codex`. Or copy the skill folder (secskills-defense/skills/triaging-security-alerts in trilwu/secskills) into .agents/skills/triaging-security-alerts in your project. Codex loads it when a task matches its description.

Can I use Triaging Security Alerts in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add trilwu/secskills --skill triaging-security-alerts -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/triaging-security-alerts, .gemini/skills/triaging-security-alerts, .github/skills/triaging-security-alerts and .opencode/skills/triaging-security-alerts in your project.

What does Triaging Security Alerts need to run?

Going by SKILL.md and its folder, Triaging Security Alerts needs the command-line tools its instructions call (curl).

Does Triaging Security Alerts access the network?

SKILL.md names 1 domain. In commands or code: defuddle.md; the agent is likely to contact it when it follows the instructions. This is read from the text; nothing was executed.

Is Triaging Security Alerts safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Triaging Security Alerts use?

Triaging Security Alerts is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Triaging Security Alerts use?

About 2.5k tokens (SKILL.md is roughly 10k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Triaging Security Alerts?

Skills that share tags, products or a category with Triaging Security Alerts: Implementing Soar Playbook With Palo Alto Xsoar (mukul975/Anthropic-Cybersecurity-Skills, 34k stars), Conducting Cloud Incident Response (mukul975/Anthropic-Cybersecurity-Skills, 34k stars), Performing Soc Tabletop Exercise (mukul975/Anthropic-Cybersecurity-Skills, 34k stars) and Incident Response (alirezarezvani/claude-skills, 28k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Triaging Security Alerts?

trilwu (a GitHub user) maintains it in trilwu/secskills, which has 157 GitHub stars. The repository holds 50 skills in this directory. The repository was last updated on September 4, 2026.

Source: trilwu/secskills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.