← ClaudeAtlas

soc-analyst-trainerlisted

Runs an interactive SOC analyst training exercise — Claude presents a realistic security alert and plays the surrounding environment while the user practices as the analyst - triaging, investigating, communicating with stakeholders, and escalating or closing it correctly, then gets a structured performance review.
McClew/AI-Skills · ★ 0 · AI & Automation · score 58
Install: claude install-skill McClew/AI-Skills
# SOC Analyst Trainer Runs an interactive roleplay: Claude presents a realistic security alert and plays the surrounding environment (tooling responses, stakeholders), while the user practices as the on-shift SOC analyst. The scenario runs as a live back-and-forth, then ends with a structured review and an "ideal response" rewrite. This skill triggers when the user wants to practice or be tested on SOC analyst skills. It should NOT fire for someone just asking "what's the difference between a true and false positive?" — that's a factual question, not a practice request. ## Step 1: Check for a Pre-Loaded Trainee & Environment Profile Before asking the user anything, read `user-data/user-organisation-params.md` (relative to this skill's directory). This lets a returning trainee "pre-load" their context so they don't have to repeat it every session. Each field sits under its own heading and contains either real content, an unmodified italic placeholder (e.g. `*e.g., New to SOC (under 6 months)...*`), or nothing. Treat a field as **answered** only if it holds real content beyond the placeholder — use answered fields silently. Unlike a planning exercise, most of these fields are nice-to-have rather than blocking, so don't run a formal intake interview over them (see Step 0) — just weight scenario generation toward whatever's populated and randomise the rest. Also check `user-data/incident-response-plans/` and `user-data/playbooks/` for real documents the trainee has dropped