kimo
TemplateKimo Defense

SOC triage template

SOC triage is a Kimo template that fuses SIEM detections, EDR telemetry and OSINT signals into one queue of scored incidents, each mapped to MITRE ATT&CK tactics and techniques. Instead of analysts reading hundreds of raw alerts, they work a short list of incidents grouped by entity and time window, ranked by a transparent score, with the ATT&CK context that tells them where in an intrusion the activity sits.

Dashboards
4
Data models
5
Metrics
6
Min setup
4
app.getkimo.com/templates/soc-triage
SOC triage
Triage queue
Open incidents
14
−5(favorable)
Median time to triage
11 min
−4 min(favorable)
Alerts per incident
9.6
+1.2(favorable)
Queue age (p90)
46 min
−12 min(favorable)

Raw alerts vs. incidents (daily)

  • Raw alerts
  • Incidents

Top incidents (fictional)

  • INC-2291 · credential access → lateral movement
    4 tactics · 23 alerts · srv-fin-02
    Score 92
  • INC-2288 · phishing → execution
    2 tactics · 9 alerts · wks-0417
    Score 71
  • INC-2284 · known-bad IP beacon
    OSINT match · 6 alerts
    Score 64
  • INC-2279 · admin tool on new host
    Allow-listed · closed
    Closed

Simulated data. Callsigns, receivers, hosts and incidents are fictional.

What’s inside

Everything the dashboards need, already modeled

Models join your raw sources, metrics are defined once in the semantic layer, and every dashboard, deck and Ask Kimo answer reads from the same definitions.

Data models

5
  • alerts
  • attack_techniques
  • incidents
  • assets
  • osint_indicators

Dashboards

4
  • Triage queue
  • ATT&CK coverage
  • Noise and efficiency
  • Sources health

Governed metrics

6
  • Incident score
  • Median time to triage
  • Alerts per incident
  • Distinct tactics per incident
  • Unmapped rules
  • Queue age
Connectors

4 sources, read-only

Connect them from the cloud, or keep databases on your own servers with Kimo Bridge — an outbound-only tunnel, so nothing has to be copied to use the template.

Setup

Live in 5 steps

  1. 1

    Connect Splunk or Elastic Security, your EDR telemetry and at least one OSINT feed (directly or through Kimo Bridge).

  2. 2

    Import your asset inventory and set criticality for key systems.

  3. 3

    Review the rule-to-ATT&CK mapping table and fill gaps for your custom rules.

  4. 4

    Adjust the grouping window and score threshold for your alert volume.

  5. 5

    Assign queue owners and notification channels, then review a week of incidents.

The details

How the template works

§01What problem does SOC triage solve?

Security teams rarely lack alerts. They lack a way to see that six alerts from three tools are one incident. This template does the correlation in a governed data model rather than in an analyst's head, and it uses a shared vocabulary for what the activity means: MITRE ATT&CK (opens in a new tab), a globally accessible knowledge base of adversary tactics and techniques based on real-world observations1.

§02How are alerts turned into scored incidents?

  1. Step 1:

    Normalize

    Map every alert to one schema: time, source tool, rule, severity, host, user, IP, and ATT&CK technique ID where the tool provides it.

  2. Step 2:

    Map to ATT&CK

    Fill missing technique IDs from a rule-to-technique table you maintain, and derive tactics from techniques. For example, Phishing (T1566) sits under Initial Access2, while Valid Accounts (T1078) spans Initial Access, Persistence, Privilege Escalation and Stealth3.

  3. Step 3:

    Group into incidents

    Cluster alerts that share a host or user within a sliding 6-hour window. One incident, many alerts, one timeline.

  4. Step 4:

    Corroborate with OSINT

    Match indicators (domains, IPs, hashes) against your OSINT feeds and threat reports; a match raises the score and attaches the source.

  5. Step 5:

    Score and rank

    Compute an additive score and send incidents above the threshold to the queue; everything else stays searchable.

Formula

Incident score=max alert severity + asset criticality + 10 × distinct tactics + OSINT match bonus

where
max alert severity
0–40, highest normalized severity in the incident
asset criticality
0–30, from your asset inventory
distinct tactics
Number of different ATT&CK tactics observed, capped at 3
OSINT match bonus
0 or 15 when an indicator matches a trusted feed

Counting distinct tactics rewards progression: an incident that shows Initial Access, then Credential Access, then Lateral Movement is more urgent than many alerts of one kind. The current Enterprise matrix lists 15 tactics, from Reconnaissance to Impact4. The tactic list evolves between ATT&CK releases, so the template stores IDs (for example TA0001) and refreshes names from the matrix.

§03Which dashboards and metrics are included?

DashboardKey views
Triage queueIncidents by score, owner, age; drill into the alert timeline
ATT&CK coverageIncidents and alerts per tactic and technique, last 30 days
Noise and efficiencyAlerts per incident, share of alerts auto-grouped, time to triage
Sources healthAlert volume and latency per tool, unmapped rules
Time to triage
median, from first alert to owner assigned
Alerts / incident
grouping ratio
Unmapped rules
rules without an ATT&CK technique
Queue age
oldest open incident above threshold

The metrics are designed to support the incident response practices in NIST SP 800-61 Revision 3, a CSF 2.0 Community Profile that treats incident response as part of cybersecurity risk management across the CSF 2.0 functions6. For a real-world shape of this setup, read how a national CERT fused SIEM and OSINT into one incident queue.

§04How do I tune it for my SOC?

Start by running the template in shadow mode for a week: incidents are built and scored but nobody is paged. Compare the queue with what analysts actually escalated, then adjust the grouping window (shorter for noisy environments), the criticality of key assets and the score threshold. Most teams also add one or two custom score components, such as a bonus when an incident touches a privileged account.

Splunk and Elastic Security for detections, EDR telemetry for endpoints, OSINT feeds for corroboration, Kafka for custom sensors.

Detection data often cannot leave your network: run the connectors through Kimo Bridge or deploy Kimo on-premise. Explore incidents from Ask Kimo with questions such as "incidents with lateral movement this week by business unit".

Frequently asked questions

Do my tools need to emit ATT&CK IDs?

No. If a detection already carries a technique ID, the template uses it; otherwise a rule-to-technique mapping table fills it in, and unmapped rules are listed on the Sources health dashboard.

How are alerts grouped into incidents?

By shared host or user within a sliding 6-hour window by default. Both the keys and the window are parameters.

Can analysts see why an incident scored high?

Yes. The score is additive and each component is shown on the incident, so analysts can see whether severity, asset criticality, tactic spread or an OSINT match drove it.

Does the template replace my SIEM?

No. It sits on top of your SIEM and EDR as a triage and reporting layer; detections and response actions stay in your security tools.

Sources

6 references
  1. MITRE ATT&CK (opens in a new tab)
    The MITRE Corporationattack.mitre.org
  2. Enterprise tactics (opens in a new tab)
    MITRE ATT&CKattack.mitre.org

    15 Enterprise tactics in ATT&CK v19.

External sources were accessed at the time of writing. Kimo product details, customers and figures in examples are illustrative unless a source is cited.

All resources
Definition
Defense

OSINT

OSINT (open-source intelligence) is intelligence produced from publicly or commercially available information to answer a specific question or requirement.

Kimo team
3 min read
Definition
Defense

Data fusion

Data fusion is the process of combining observations from multiple sources about the same objects or events into one estimate that is more accurate, complete or trustworthy than any single source.

Kimo team
3 min read

More Defense Intelligence templates

All templates

Deploy the soc triage template in Kimo

Open it on simulated data first, then point it at your own feeds — in Kimo’s cloud or on your infrastructure through Kimo Bridge.