SOC Alert Triage
Pick the alert category, answer a few questions, run the suggested queries and get a disposition, next steps, ATT&CK references and a ticket note.
Runs entirely in your browser. Nothing you select or type is stored or sent anywhere.
1. Quick risk score
Optional: alert details to fill the query placeholders
Values replace placeholders such as <USER> or [IP] in the queries and ticket note shown below. Empty fields leave the placeholder in place.
2. Alert or log category
How it works
Triage runs in two stages, then combines them into one result.
- Context. A few multiple-choice questions about the alert (type, volume, source, asset, scope). Each answer adds points; the total maps to a context severity (Info, Low, Medium, High, Critical) and a response level: Monitor, Investigate, Escalate or Contain immediately. This stage covers six sources: authentication, endpoint/EDR, network/firewall, email, web application and cloud/IAM.
- Evidence checks. For authentication, endpoint and email alerts, yes/no questions that you answer by running the QRadar AQL or KQL query shown with each question. The path ends in a disposition: P1 escalate, P2 investigate, false positive or benign, with the actions to take and a ticket template. Answers already given by the alert type are filled in for you.
The disposition says whether the alert is a true positive; the context severity and the quick risk score say how fast to act on it. The quick risk score adds asset criticality (1–4), threat intel confidence (1–3), attack phase (1–4) and data sensitivity (1–4): 13–15 is P1, 10–12 P2, 7–9 P3, 5–6 P4, 4 P5.
The queries are starting templates. Field and property names depend on your log sources, DSMs and connectors (for example the Windows event ID property in QRadar, or SigninLogs living in Microsoft Sentinel rather than Defender XDR advanced hunting), so adjust them before relying on an empty result. Look up the listed techniques offline in ATT&CK Technique Search.