Defensive analysis in depth
Triage, IOC work, detection engineering, IR, prioritization, and threat intel in Defensive mode.
Last updated · September 2026
On this page
Defensive mode is intended for SOC, incident response, detection engineering, vulnerability management, threat intelligence, and security operations. Give it artifacts and ask it to improve a decision, not to replace one.
| Task | How to use it |
|---|---|
| Alert triage | Summarize the alert, reconstruct the likely sequence, identify affected entities, classify confidence, define the next three checks. |
| IOC analysis | Normalize indicators, group related observations, identify likely false positives, suggest detection and enrichment paths. |
| Detection engineering | Review logic, assumptions, data-source dependencies, blind spots, tuning opportunities, and test cases. |
| Incident response | Build a timeline, identify containment options, list evidence preservation requirements, separate urgent from follow-up work. |
| Vulnerability prioritization | Combine technical exposure, asset criticality, exploitability evidence, compensating controls, and remediation feasibility. |
| Threat intelligence | Turn reports and indicators into hypotheses, collection requirements, and defensive actions. |
Defensive analysis discipline
A clean result is not proof that an environment is clean. Require explicit evidence references and ask what telemetry would falsify the leading hypothesis.
Was this page helpful?

