§01What problem does SOC triage solve?
Security teams rarely lack alerts. They lack a way to see that six alerts from three tools are one incident. This template does the correlation in a governed data model rather than in an analyst's head, and it uses a shared vocabulary for what the activity means: MITRE ATT&CK (opens in a new tab), a globally accessible knowledge base of adversary tactics and techniques based on real-world observations1Source 1 · The MITRE CorporationMITRE ATT&CKattack.mitre.org.
§02How are alerts turned into scored incidents?
- Step 1:
Normalize
Map every alert to one schema: time, source tool, rule, severity, host, user, IP, and ATT&CK technique ID where the tool provides it.
- Step 2:
Map to ATT&CK
Fill missing technique IDs from a rule-to-technique table you maintain, and derive tactics from techniques. For example, Phishing (T1566) sits under Initial Access2Source 2 · MITRE ATT&CKPhishing, Technique T1566 — Enterpriseattack.mitre.org, while Valid Accounts (T1078) spans Initial Access, Persistence, Privilege Escalation and Stealth3Source 3 · MITRE ATT&CKValid Accounts, Technique T1078 — Enterpriseattack.mitre.org.
- Step 3:
Group into incidents
Cluster alerts that share a host or user within a sliding 6-hour window. One incident, many alerts, one timeline.
- Step 4:
Corroborate with OSINT
Match indicators (domains, IPs, hashes) against your OSINT feeds and threat reports; a match raises the score and attaches the source.
- Step 5:
Score and rank
Compute an additive score and send incidents above the threshold to the queue; everything else stays searchable.
Incident score=max alert severity + asset criticality + 10 × distinct tactics + OSINT match bonus
- max alert severity
- 0–40, highest normalized severity in the incident
- asset criticality
- 0–30, from your asset inventory
- distinct tactics
- Number of different ATT&CK tactics observed, capped at 3
- OSINT match bonus
- 0 or 15 when an indicator matches a trusted feed
Counting distinct tactics rewards progression: an incident that shows Initial Access, then Credential Access, then Lateral Movement is more urgent than many alerts of one kind. The current Enterprise matrix lists 15 tactics, from Reconnaissance to Impact4Source 4 · MITRE ATT&CKEnterprise tacticsattack.mitre.org. The tactic list evolves between ATT&CK releases, so the template stores IDs (for example TA0001) and refreshes names from the matrix.
§03Which dashboards and metrics are included?
| Dashboard | Key views |
|---|---|
| Triage queue | Incidents by score, owner, age; drill into the alert timeline |
| ATT&CK coverage | Incidents and alerts per tactic and technique, last 30 days |
| Noise and efficiency | Alerts per incident, share of alerts auto-grouped, time to triage |
| Sources health | Alert volume and latency per tool, unmapped rules |
The metrics are designed to support the incident response practices in NIST SP 800-61 Revision 3, a CSF 2.0 Community Profile that treats incident response as part of cybersecurity risk management across the CSF 2.0 functions6Source 6 · NIST, 2025SP 800-61 Rev. 3: Incident Response Recommendations and Considerations for Cybersecurity Risk Management: A CSF 2.0 Community Profilecsrc.nist.gov. For a real-world shape of this setup, read how a national CERT fused SIEM and OSINT into one incident queue.
§04How do I tune it for my SOC?
Start by running the template in shadow mode for a week: incidents are built and scored but nobody is paged. Compare the queue with what analysts actually escalated, then adjust the grouping window (shorter for noisy environments), the criticality of key assets and the score threshold. Most teams also add one or two custom score components, such as a bonus when an incident touches a privileged account.
Detection data often cannot leave your network: run the connectors through Kimo Bridge or deploy Kimo on-premise. Explore incidents from Ask Kimo with questions such as "incidents with lateral movement this week by business unit".
Frequently asked questions
Do my tools need to emit ATT&CK IDs?
How are alerts grouped into incidents?
Can analysts see why an incident scored high?
Does the template replace my SIEM?
Sources
6 references- MITRE ATT&CK (opens in a new tab)The MITRE Corporationattack.mitre.org
- Phishing, Technique T1566 — Enterprise (opens in a new tab)MITRE ATT&CKattack.mitre.org
- Valid Accounts, Technique T1078 — Enterprise (opens in a new tab)MITRE ATT&CKattack.mitre.org
- Enterprise tactics (opens in a new tab)MITRE ATT&CKattack.mitre.org
15 Enterprise tactics in ATT&CK v19.
- Best Practices for MITRE ATT&CK Mapping (opens in a new tab)CISA2023cisa.gov
- SP 800-61 Rev. 3: Incident Response Recommendations and Considerations for Cybersecurity Risk Management: A CSF 2.0 Community Profile (opens in a new tab)NIST2025csrc.nist.gov
External sources were accessed at the time of writing. Kimo product details, customers and figures in examples are illustrative unless a source is cited.


