Skip to main content
32 skills tagged with this outcome.

Acronis Cyber Protect

An Acronis Cyber Protect alert arrived — first decide whether it is a backup failure or an Active Protection (anti-ransomware/security) detection, then run the matching discipline; the two must never be triaged the same way.

After-Hours Coverage Handoff

Build the end-of-business handoff to on-call or after-hours coverage — open urgent work, expected client callbacks, and site notes the night crew needs.

After-Hours Voicemail Digest

Build the morning digest of overnight voicemails and after-hours calls — urgent items first, callbacks owed with deadlines, and which tickets were created. Use for "what came in overnight on the phones" or a scheduled 7am flow.

APC UPS Alerts

An APC UPS alert arrived — on-battery event, low runtime, self-test failure, or replace-battery indicator. Separate utility problems from UPS problems, run the battery-replacement workflow, and verify graceful shutdown actually works.

AV/EDR Agent Offline Alert

Triage an "endpoint protection agent not reporting" alert from any AV/EDR product — decide whether the device is off or up-with-a-dead-agent, quantify how long the endpoint has been unprotected, and route on that protection-gap. Use for agent-offline, agent-not-checked-in, or sensor-unhealthy alerts.

Axcient Backup Alerts

An Axcient x360Recover alert needs triage — distinguish appliance-based vs Direct-to-Cloud failure families, verify retention is doing what the client's design says, and state the last recoverable point.

Backup Missed vs Failed Alert

Distinguish a backup job that never ran (missed) from one that ran and errored (failed) — two different diagnoses and routes — and always state the client's actual exposure via last-known-good. Use when a backup alert is ambiguous about whether the job executed at all.

Certificate Expiry Alert

Triage a certificate-expiring/expired alert — tier urgency by days remaining, identify what the certificate secures and who owns renewal, and route into the renewal work. Use when a cert-expiry alert fires from monitoring, Liongard, or a vendor console.

Cove Data Protection Alerts

An N-able Cove Data Protection backup ticket arrived — classify the failure family, verify recoverability rather than assuming it, and keep archive/retention sessions straight from standard sessions. Verify against N-able's current Cove documentation.

Dark Web Alert Lifecycle

A dark-web or credential-exposure monitoring alert arrived — age it, close stale exposures with a documented note, and notify affected users with rotation guidance on fresh ones.

Datto BCDR Verification

A Datto BCDR alert needs working — screenshot-verification failure, local backup vs off-site (cloud) sync lag, or virtualization-test cadence questions. Separate "backup ran" from "backup boots" and state the real recovery position.

Disk Space Alert

Triage a low-disk-space alert regardless of which monitor raised it — separate threshold noise from real pressure, read the growth rate from the alert history, and route with ranked consumer hypotheses. Use when a disk/volume-space alert lands and needs a verdict, not yet a cleanup.

Domain Expiry Alert Lifecycle

A registrar expiry, renewal, or "your domain is about to lapse" notice arrived as a ticket — verify the sender is the real registrar FIRST (renewal-invoice scams are a classic BEC lure), confirm the actual expiry date independently, identify who owns the renewal, and route with a timeline.

Email Header Analysis

Someone pasted raw email headers and wants a verdict — parse authentication results, the received path, and spoof indicators, and return a verdict with explicit confidence.

High CPU/Memory Alert

Triage a CPU or memory threshold alert — separate a transient spike from sustained pressure using alert history, offer top-consumer hypotheses by device role, and route servers vs workstations differently. Use when a performance-threshold alert lands from any monitor.

Kaseya Dark Web Monitoring

A Dark Web ID (Kaseya) compromise alert arrived — parse the vendor's alert anatomy (source, date, data classes), then run the dark-web-alert-lifecycle age/notify logic. Same hard no-cracking policy.

M365 SaaS Backup

A SaaS backup ticket arrived (M365/Google Workspace backup products generically) — a point-in-time restore request, a protection-scope/license reconciliation, or a job failure. Verify authorization before restores and reconcile protected seats against real users.

M365 Tenant Health Report

Produce an advisory digest of a client tenant's Microsoft 365 Service Health incidents and Message Center posts — what's degraded now and what change is coming — as a plain-language brief, not an action. Use when someone asks "is anything wrong with <client>'s M365," "what Microsoft changes are coming," or wants a periodic tenant health/roadmap digest.

MDR Client Onboarding

A client is being onboarded to a new MDR/SOC service — scope the assets, wire alert routing into the desk, record escalation contacts and authority, and set baseline-noise expectations for the first weeks.

Notion Client Runbook Database

Create and maintain a client-runbooks database in Notion — one entry per client per system — and update entries when a ticket reveals an environment fact has changed. Use when asked to "set up a client runbook database", "update <client>'s runbook", or "keep our client docs in Notion current".

Patch Failure Alert

Triage a patch/update-failure alert — separate a one-off the next cycle will fix from a repeat offender, detect reboot-pending as the usual culprit, and correlate against the device's patch window. Use when a patch-failed or update-failed alert lands, from any patch engine.

Quarantine Release Request

Someone asked to release a quarantined email — verify the requester, assess why the filter caught it, and recommend release or refusal with the reasoning documented.

RAID Degradation Alert

Triage a RAID degraded/failed-member alert with zero-margin urgency — a degraded array is one failure from data loss — and enforce the verify-backups-BEFORE-rebuild rule. Use for any degraded-array, failed-disk-in-array, or rebuild alert from a server, NAS, or storage controller.

SD-WAN / Multi-Circuit Monitoring

Review a multi-circuit or SD-WAN site's connectivity — confirm each circuit is up, failover actually works, and open the right ISP escalation when a circuit is down or degraded. Use when a site has multiple WAN links, someone reports one circuit down, or you're verifying failover posture.

Supporting Logistics and Trucking Clients

Vertical pack for trucking, freight, and logistics clients — TMS platforms (McLeod, Trimble/TMW-class), ELD/telematics fleets (Samsara, Motive-class) and DOT/HOS compliance adjacency, driver devices in the field, EDI with shippers and brokers, and the 24/7 dispatch-desk rhythm. Load when the client is a carrier, broker, or 3PL, or the ticket names a TMS, ELDs, dispatch, or driver tablets.

Supporting Medical Clinics

Vertical pack for medical-clinic and physician-practice clients — the EMR/EHR stack (eClinicalWorks, Athenahealth-class), e-prescribing and lab interfaces, telehealth, HIPAA/PHI ticket hygiene, and on-call urgency. Load when the client is a medical practice or the ticket names an EMR, e-prescribing, or telehealth platform.

Supporting Senior Living Communities

Vertical pack for senior-living, assisted-living, and skilled-nursing clients — EHR/eMAR platforms (PointClickCare, MatrixCare-class) and the med-pass clock, nurse-call and life-safety adjacency, resident wifi vs clinical network separation, HIPAA, and night-shift coverage realities. Load when the client is a senior-living community or the ticket names an eMAR, nurse call, or resident network.

Synology NAS Alerts

A Synology NAS alert needs working — degraded RAID/storage pool, disk health warnings, volume nearly full, or DSM update decisions. Treat a degraded array as one failure from data loss and keep disk-replacement discipline.

Typosquat Domain Alert

A lookalike or typosquatted domain impersonating a client was reported or detected — gather registrar and DNS facts without visiting it, gauge attack capability, and draft the client warning.

Veeam Job Failures

A Veeam backup job failed or warned — classify the failure into the Veeam taxonomy (VSS, credentials, repository, network), apply retry discipline instead of blind reruns, and state the client's real exposure via the last successful restore point.

Voicemail to Ticket

Convert a voicemail transcription into a ticket with a callback commitment — urgency read from what the caller said, not from tone guesses. Use when a voicemail lands as ticket/thread content or is pasted in.

Zapier PagerDuty On-Call

Page the on-call engineer for a P1 via PagerDuty, tell the requester who's on call and that they've been paged, and mirror the ack/resolve loop back to the ticket. Use for "page on-call", "who is on call right now", or wiring P1 paging into an after-hours flow.