Sysdig Runtime Investigate

Use this skill when investigating a runtime threat detected by Sysdig end-to-end. Surfaces the highest-priority threat, scores vulnerability vs runtime correlations on a 1-5 confidence scale, deep-dives into network blast radius or suspicious-binary VirusTotal lookups depending on the event class, reconstructs the affected workload's activity audit trail (commands, connections, file accesses) as a timeline around the detection, and hands the case off to Jira or PagerDuty. Triggers on: "investigate runtime threat", "what is this Falco alert", "triage this SOC alert", "analyze runtime incident". Not for vulnerability prioritization (use `sysdig-investigate`) or remediation (use `sysdig-remediate`).

sysdig Updated

File contents

sysdig/skills/tree/main/skills/sysdig-runtime-investigate commit ef6dba974b

Frequently asked questions

npx skillmds@latest add sysdig/sysdig-runtime-investigate