Templates / Incident & escalation / security-alert-triage

Security Alert Triage

Triages alerts from a SIEM. Each alert is enriched with threat intelligence and scored with a FEEL script; low scores are closed as false positives. Real threats are contained in a sub-process that isolates the host and resets credentials — if isolation fails it throws CONTAINMENT_FAILED and a tier-2 analyst contains it by hand — and every contained alert opens a case.

error boundarysub-processsecuritysoc
Open in editor Download .bpmn
casen template use security-alert-triage
Contain threat false-positive threat yes no Enrich withthreat intel Score alert Close asfalsepositive Containmanually Openincidentcase Isolate host Resetcredentials Security alert received Risk score ≥ 20? Closed as false positive Containment failed Case opened Isolated?

Scenarios · 3

  • A malicious login is contained automatically score-alert → isolate-host → reset-credentials → open-case → case-opened
  • A low-scoring alert is closed score-alert → close-alert → alert-closed
  • Isolation fails and an analyst contains the host by hand isolate-host → containment-failed → on-containment-failed → manual-containment → open-case

Job types · 5

  • case-create Open incident case
  • edr-host-isolate Isolate host
  • iam-credentials-reset Reset credentials
  • siem-alert-close Close as false positive
  • threat-intel-enrich Enrich with threat intel

Files · 2

Every scenario passes on @bpmnkit/engine's runScenario in the package's tests. casen template use security-alert-triage [dir] writes the files above into your project — see the templates guide for running the scenarios and deploying.