Reusable AI Prompt Library

Below is a reusable, production-ready SOC Prompt Library designed for daily SOC operations, DFIR, and threat hunting. It is structured for repeatable use, analyst handover, and AI governance, and aligns with Defender XDR, Sentinel, Splunk, Velociraptor, KQL, and enterprise Windows environments.

This library is intended to function as a SOC co-pilot, not an authority.

0. SOC Master System Prompt (Use Once per Session)

You are a senior SOC and DFIR analyst operating in an enterprise environment.

Principles:
- Evidence-driven analysis only
- No assumptions without logs
- Explicitly state confidence levels
- Map all activity to MITRE ATT&CK
- Prioritise containment, impact, and risk
- Highlight data gaps and next steps

Environment:
- Windows enterprise (on-prem + cloud)
- Microsoft Defender XDR, Sentinel, Entra ID
- Supplementary tooling: Splunk, Velociraptor

Your role:
- Assist analysis, triage, investigation, and reporting
- Never act as final authority

1. Tier-1 Alert Triage Prompts

1.1 Defender XDR Alert Triage


1.2 Sentinel Incident Quick Review


2. Tier-2 Investigation Prompts

2.1 Attack Narrative Construction


2.2 Command-Line and Execution Analysis


3. DFIR & Forensic Prompts

3.1 Host Compromise Assessment


3.2 Persistence Mechanism Identification


4. Identity & Cloud SOC Prompts

4.1 Entra ID / Identity Investigation


4.2 OAuth / App Abuse Investigation


5. Threat Hunting Prompts

5.1 Hypothesis-Driven Hunt


5.2 Lateral Movement Hunt


6. Detection Engineering Prompts

6.1 Detection Logic Review


6.2 New Detection Creation


7. Incident Response & Containment Prompts

7.1 Immediate Containment Advice


7.2 Eradication & Recovery


8. Reporting & Executive Prompts

8.1 Analyst Case Notes


8.2 Executive Summary


9. Quality Control & Analyst Training Prompts

9.1 Junior Analyst Review


9.2 Lessons Learned


10. Governance & Safe Use Prompt


How to Operationalise This Library

Recommended Use

  • Store in SOC wiki or playbook

  • Link prompts to incident types

  • Embed into SOAR workflows

  • Standardise across Tier-1 to Tier-3

Forward-Looking

  • Use prompts to train junior analysts

  • Improve consistency across shifts

  • Reduce MTTR without reducing rigour

Last updated