Run AI-assisted security triage with role-based SOC runbooks from ai-runbooks
Use ai-runbooks to give AI assistants role-specific SOC personas, investigation steps, and incident-response procedures for structured security triage.
Prerequisites
Git repository checkout, a supported AI assistant configuration directory, security operations context
Installation
Choose whichever fits your setup:
- Copy this skill folder into your local skills directory.
- Clone the repo and symlink or copy the skill into your agent workspace.
- Add the repo as a git submodule if you manage shared skills centrally.
- Install it through your internal provisioning or packaging workflow.
- Download the folder directly from GitHub and place it in your skills collection.
Install command or upstream instructions:
Clone the repository, verify the rules_bank symlinks for the supported assistant directories, then load the relevant persona and runbook content into the assistant workflow as documented in the repository.