Now liveThe Skillselion MCP - thousands of ranked skills, loaded into your agent mid-task. No install.Get it →
daemon-blockint-tech avatar

Soc Analyst

  • 29 installs
  • 7 repo stars
  • Updated May 20, 2026
  • daemon-blockint-tech/agentic-enteprises-skill

Security operations and threat detection in enterprise environments.

About

SOC-analyst skill provides security operations center workflows and threat detection. Developers use it to build security monitoring and incident response systems.

  • Security incident detection and response
  • Threat hunting and analysis

Soc Analyst by the numbers

  • 29 all-time installs (skills.sh)
  • Ranked #1,502 of 2,203 Security skills by installs in the Skillselion catalog
  • Data as of Jul 29, 2026 (Skillselion catalog sync)
npx skills add https://github.com/daemon-blockint-tech/agentic-enteprises-skill --skill soc-analyst

Add your badge

Show developers this skill is listed on Skillselion. Paste this into your README.

Listed on Skillselion
Installs29
repo stars7
Last updatedMay 20, 2026
Repositorydaemon-blockint-tech/agentic-enteprises-skill

What it does

Security operations and threat detection in enterprise environments.

Files

SKILL.mdMarkdownGitHub ↗

SOC Analyst

When to Use

  • Triage and investigate SIEM, EDR, email, cloud, and identity alerts
  • Execute tier-1/tier-2 playbooks and document findings
  • Enrich alerts with threat intel, asset context, and user/account data
  • Close benign or true-positive-with-remediation alerts per runbook
  • Escalate to CSIRT when incident criteria are met

When NOT to Use

  • Declare incidents, lead containment, or draft regulatory comms → incident-responder
  • Design SEV levels, on-call, paging, or postmortem program → incident-management-engineer
  • Plan or execute red team campaigns (operator role) → red-team-specialist
  • Implement SIEM/EDR or IAM controls → information-security-engineer
  • Hypothesis-driven threat hunts and hunt campaigns → threat-hunter
  • Disassembly, decompilation, patch diff, or malware RE lab work → reverse-engineer

Related skills

NeedSkill
Escalate declared security incidentincident-responder
Incident program, escalation matrixincident-management-engineer
Security strategy and IR policycybersecurity
Red team / purple team exercise designred-team-specialist
Tooling implementation (SIEM, EDR, SOAR)information-security-engineer
Cloud audit and account forensicscloud-security-engineer
Proactive threat hunts and hunt campaignsthreat-hunter
Detection tuning and DFIR-style investigationdefensive-security-analyst
Disk/memory forensics and chain of custodydigital-forensics-analyst
Binary/protocol RE, patch diff, YARA from samplesreverse-engineer
Vetted IOC/TTP packages and tactical intel for enrichmentcti-analyst

Handoff to threat hunting

Escalate to threat-hunter when alerts cluster into a plausible campaign, detections are evasive, leadership requests a proactive hunt, or post-incident pattern expansion is needed. Include UTC window, entities, IOCs, what was ruled out, and linked tickets.

Handoff to CSIRT

Escalate to incident-responder when incident declaration criteria are met (see incident-responder/references/incident_declaration_and_severity.md). Include UTC timestamps, affected entities, IOCs, evidence links, and open questions. Confirmed compromises found during hunts also route through this path.

Related skills

Securityauditsecrets

This week in AI coding

Five minutes, every Monday - the tools, releases and tactics for developers.

unsubscribe anytime.