适用对象
- SOC analysts and security engineers
- Managed security providers
- Detection-engineering teams
- Incident-response leads
Tetrees AI Pack · TAIP/1 · v1.0.0
A defensive SOC investigation pack that fuses alert evidence, maps behavior to MITRE ATT&CK, grades confidence, and proposes approval-gated containment with a replayable ledger.
Tetrees Agent 指南
Security queues mix duplicate alerts, incomplete telemetry, adversarial noise, and high-impact actions; a fast narrative without evidence preservation can misclassify incidents or destroy forensic context.
可从以下请求开始,再替换为你的具体内容。
An impossible-travel alert, MFA reset, and mailbox rule change may belong to one account-takeover incident.
Correlate these identity, email, and VPN events. Build the timeline, map only supported ATT&CK techniques, grade confidence, and propose safe containment requiring approval.
预期结果: A deduplicated incident, entity timeline, evidence citations, supported technique map, benign alternatives, and approval-gated containment with preservation steps.
A reported message contains a suspicious link, but the evidence does not yet show execution or credential use.
Analyze the attached message metadata, URL observations, endpoint telemetry, and identity events. State what is proven, what is suspected, and the next safe checks.
预期结果: A staged phishing investigation, evidence gaps, confidence and severity separation, escalation criteria, and no unsupported host isolation.
在 Agent Studio 中选择 OpenAI、Claude 或 Z.AI,然后使用 Tetrees 积分或 BYOK 运行。
托管运行仅使用此签名工具集。本地 MCP 可添加由你单独配置和批准的工具。
Agent AVCP
测试的 TAIP 制品与本报告及平台签名绑定。分数反映测试证据,不保证未来每次模型输出。
总分
9.5
满分 10 分
必需门槛
请登录后运行或获取此包。
暂无评价。