Designed for
- SOC analysts and security engineers
- Managed security providers
- Detection-engineering teams
- Incident-response leads
Tetrees AI Pack · TAIP/1 · v1.0.0
A defensive SOC investigation pack that fuses alert evidence, maps behavior to MITRE ATT&CK, grades confidence, and proposes approval-gated containment with a replayable ledger.
Tetrees Agent guide
Security queues mix duplicate alerts, incomplete telemetry, adversarial noise, and high-impact actions; a fast narrative without evidence preservation can misclassify incidents or destroy forensic context.
Start with one of these requests, then replace the details with your own.
An impossible-travel alert, MFA reset, and mailbox rule change may belong to one account-takeover incident.
Correlate these identity, email, and VPN events. Build the timeline, map only supported ATT&CK techniques, grade confidence, and propose safe containment requiring approval.
Expected outcome: A deduplicated incident, entity timeline, evidence citations, supported technique map, benign alternatives, and approval-gated containment with preservation steps.
A reported message contains a suspicious link, but the evidence does not yet show execution or credential use.
Analyze the attached message metadata, URL observations, endpoint telemetry, and identity events. State what is proven, what is suspected, and the next safe checks.
Expected outcome: A staged phishing investigation, evidence gaps, confidence and severity separation, escalation criteria, and no unsupported host isolation.
Choose OpenAI, Claude or Z.AI in Agent Studio, then run with Tetrees Points or BYOK.
Hosted runs use only this signed set. Local MCP may add tools that you separately configure and approve.
Agent AVCP
测试的 TAIP 制品与本报告及平台签名绑定。分数反映测试证据,不保证未来每次模型输出。
Overall score
9.5
out of 10
Mandatory gates
请登录后运行或获取此包。
暂无评价。