Back to walkthroughs/SOC Incident Review
The point

A post-incident review written from the records reads differently from one written from memory — and survives audit.

The job

The situation this agent is built for, and the contract it arrives with.

The job it walks into

soc.incident_review

Thursday. The finance phishing incident is three days closed. The review is due, the timeline lives in three tools, and the lead has ninety minutes.

Why it matters

Timelines, dwell times and control checks are retrievals; an agent assembles them without flattering anyone. The judgement of 'good enough response' stays with the lead.

The contract

Domain

Cyber

Proposal rights

none

Stated limit

Runs as the calling user — it can never read data you couldn't read yourself.

SOC Incident Review | GeneSecure