Templates / Incident & escalation / security-alert-triage
Security Alert Triage
Triages alerts from a SIEM. Each alert is enriched with threat intelligence and scored with a FEEL script; low scores are closed as false positives. Real threats are contained in a sub-process that isolates the host and resets credentials — if isolation fails it throws CONTAINMENT_FAILED and a tier-2 analyst contains it by hand — and every contained alert opens a case.
Scenarios · 3
- A malicious login is contained automatically score-alert → isolate-host → reset-credentials → open-case → case-opened
- A low-scoring alert is closed score-alert → close-alert → alert-closed
- Isolation fails and an analyst contains the host by hand isolate-host → containment-failed → on-containment-failed → manual-containment → open-case
Job types · 5
-
case-createOpen incident case -
edr-host-isolateIsolate host -
iam-credentials-resetReset credentials -
siem-alert-closeClose as false positive -
threat-intel-enrichEnrich with threat intel
Files · 2
- security-alert-triage.bpmn Process model
- security-alert-triage.bpmn.tests.json Test scenarios (runScenario format)
Every scenario passes on @bpmnkit/engine's runScenario in the
package's tests. casen template use security-alert-triage [dir] writes the files above
into your project — see the templates guide for running
the scenarios and deploying.