Dành cho
- SOC analysts and security engineers
- Managed security providers
- Detection-engineering teams
- Incident-response leads
Tetrees AI Pack · TAIP/1 · v1.0.0
A defensive SOC investigation pack that fuses alert evidence, maps behavior to MITRE ATT&CK, grades confidence, and proposes approval-gated containment with a replayable ledger.
Hướng dẫn Tetrees Agent
Security queues mix duplicate alerts, incomplete telemetry, adversarial noise, and high-impact actions; a fast narrative without evidence preservation can misclassify incidents or destroy forensic context.
Bắt đầu với một yêu cầu bên dưới rồi thay chi tiết bằng dữ liệu của bạn.
An impossible-travel alert, MFA reset, and mailbox rule change may belong to one account-takeover incident.
Correlate these identity, email, and VPN events. Build the timeline, map only supported ATT&CK techniques, grade confidence, and propose safe containment requiring approval.
Kết quả dự kiến: A deduplicated incident, entity timeline, evidence citations, supported technique map, benign alternatives, and approval-gated containment with preservation steps.
A reported message contains a suspicious link, but the evidence does not yet show execution or credential use.
Analyze the attached message metadata, URL observations, endpoint telemetry, and identity events. State what is proven, what is suspected, and the next safe checks.
Kết quả dự kiến: A staged phishing investigation, evidence gaps, confidence and severity separation, escalation criteria, and no unsupported host isolation.
Chọn OpenAI, Claude hoặc Z.AI trong Agent Studio rồi chạy bằng Điểm Tetrees hoặc BYOK.
Chạy trên máy chủ chỉ dùng bộ công cụ đã ký này. MCP cục bộ có thể thêm công cụ do bạn tự cấu hình và phê duyệt.
Agent AVCP
TAIP đã kiểm tra được liên kết với báo cáo và chữ ký nền tảng. Điểm số là bằng chứng kiểm thử, không bảo đảm mọi phản hồi tương lai.
Điểm tổng
9.5
trên 10
Cổng bắt buộc
Đăng nhập để chạy hoặc nhận gói.
Chưa có đánh giá.