Summary
- Security Operations Center skill for alert triage, detection engineering, incident response, log analysis, threat hunting, SIEM queries, EDR investigation, timeline building, IOC handling, escalation notes, containment recommendations, and analyst-ready reporting.
- Use for blue-team operations, suspicious event analysis, and defensive cybersecurity workflows.