correlation-insights
Installation
SKILL.md
Security Incident Correlation Insights
Overview
This skill enables SOC analysts to correlate security incidents with related events, vulnerabilities, and threat intelligence across the ServiceNow Security Operations portfolio. By identifying shared indicators of compromise (IOCs), overlapping timelines, and common attack vectors, analysts can uncover broader attack campaigns and prioritize response efforts.
Key capabilities:
- Cross-reference security incidents by shared observables (IPs, domains, file hashes)
- Link vulnerabilities to active exploitation in security incidents
- Identify recurring attack patterns across time periods
- Surface related incidents that may be part of a coordinated campaign
- Enrich incident context with threat intelligence data
When to use: During active incident investigation, threat hunting, or periodic security portfolio reviews to identify connections between seemingly isolated events.