log-triage
Installation
SKILL.md
Log Triage
Identity-first context: the bulk of modern incidents starts or escalates via identity providers. Logs are the truth source — UIs are stale snapshots. This skill covers audit/identity logs from the major IdPs; network logs and endpoint EDR touch on this but live in other skills.
When to use
A log-triage question begins with "something is odd in the logs, take a look". This skill provides, per provider, the pattern set you can use to triage where people get lost in volume.
Triggers on:
- A question like "look at these CloudTrail events", "is this Azure AD sign-in anomaly real", "Google Workspace audit log has N login failures", "what is the anomaly here in Okta", "compromised-account investigation".
- A handoff from
detection-engineer(rule fired, asks for deeper triage),ir-runbook(incident investigation),ioc-hunter(IOC match in an identity log). - A proactive hunting session focused on identity anomalies — overlap with
threat-hunt. - A post-incident investigation where the identity path must be reconstructed for
forensics-assistor regulatory reporting.