correlation-insights

Installation
SKILL.md

Security Incident Correlation Insights

Overview

This skill enables SOC analysts to correlate security incidents with related events, vulnerabilities, and threat intelligence across the ServiceNow Security Operations portfolio. By identifying shared indicators of compromise (IOCs), overlapping timelines, and common attack vectors, analysts can uncover broader attack campaigns and prioritize response efforts.

Key capabilities:

  • Cross-reference security incidents by shared observables (IPs, domains, file hashes)
  • Link vulnerabilities to active exploitation in security incidents
  • Identify recurring attack patterns across time periods
  • Surface related incidents that may be part of a coordinated campaign
  • Enrich incident context with threat intelligence data

When to use: During active incident investigation, threat hunting, or periodic security portfolio reviews to identify connections between seemingly isolated events.

Prerequisites

Installs
29
GitHub Stars
37
First Seen
Apr 29, 2026
correlation-insights — happy-technologies-llc/happy-platform-skills