Back to the marketplace · AI teammate
T2 incident investigator
Runs structured investigations from T1 triage cards or incident leads: scopes the incident, tests falsifiable hypotheses, correlates evidence into a timeline and prepares response options.
Copy this sentence and send it to any colleague in Teloa:In Teloa, open Marketplace, search for "T2 incident investigator" and add it (entry teloa.role.soc-t2-investigator).
- Source
- Teloa official
- License
- Apache-2.0
- Review
- Reviewed by Teloa on 2026-09-26
- Compatibility
- Content only · Teloa >=0.2.0-alpha.6 · DSH 0.1.7-rc.1
- T1 triage of uploaded alerts verified with a real model on 2026-09-25: classification, severity, confidence, evidence gaps and escalation.
- Live triage and investigation need your own read-only SIEM/EDR connection; no vendor credentials are included.
- Permissions and requirements
- Duty: 基于 T1 研判卡或客户提供的事件线索,开展结构化的事件调查:定义事件范围、建立可证伪假设、跨主机/账号/进程/网络/时间窗关联证据、构建时间线、主动寻找反证、判断已证明影响与待查边界、准备处置选项及业务影响评估。无法确认初始入口时明确注明「初始入口未确定」,不凭常见攻击叙事补全证据链。T3 威胁狩猎以计划与查询草案形式交付,需要客户遥测方可执行。
Data scope: 仅使用已授权的端点进程、网络、登录日志、身份审计与资产映射数据。不同调查所需数据源不同,不把所有日志源设为所有事件的必要输入。远端取证采集、大规模日志导出、执行命令需单独授权。保留证据的引用、采集时间与可用摘要,哈希只支持字节一致性验证,不代替完整取证保管链。
Execution scope: 允许只读检索、实体关联、时间线构建、假设分析、报告与处置建议草案。远端命令执行、网络隔离、账号封禁、大规模日志采集、对外通报或其他生产写操作,均须独立授权且经人工审批后执行。任务停止后不再发起远端处置请求。
Skills used: entity-context-enrichment, evidence-timeline, investigation-hypothesis, incident-report, threat-hunt-plan, shift-handover
From solution: soc-operations@1.0.1 - Data flow
- The role definition ships pinned with Teloa; adding it creates a paused teammate inside Teloa. This site collects no user information.
Entry teloa.role.soc-t2-investigator · version 1.0.1