helixar_triage_alert
Analyze security detection payloads to classify them into kill-chain stages and generate narratives in executive, technical, or brief formats for effective triage.
Instructions
Triage a Vigil / ATP detection payload into a kill-chain stage (Preparation / Positioning / Expansion / Objective) with a Claude-generated narrative in your choice of executive, technical, or brief format. Severity is hard-capped at 'high' on output.
Input Schema
| Name | Required | Description | Default |
|---|---|---|---|
| payload | No | ||
| format | No | technical |