Skip to main content
45 skills in this category.

1Password Business

A 1Password Business rollout or admin ticket arrived — vault and group structure, sharing discipline, the Emergency Kit and admin/recovery-group account recovery, and offboarding via suspend-then-recover. Verify against 1Password's current documentation.

Abnormal Security

An Abnormal email case landed — read its account-takeover and BEC/behavioral signals, treat an ATO case as an identity incident (not just an email one), and follow through on what auto-remediation didn't cover.

Acronis Cyber Protect

An Acronis Cyber Protect alert arrived — first decide whether it is a backup failure or an Active Protection (anti-ransomware/security) detection, then run the matching discipline; the two must never be triaged the same way.

APC UPS Alerts

An APC UPS alert arrived — on-battery event, low runtime, self-test failure, or replace-battery indicator. Separate utility problems from UPS problems, run the battery-replacement workflow, and verify graceful shutdown actually works.

Arctic Wolf MDR

An Arctic Wolf escalation or ticket arrived — respect what their SOC already triaged, pick up exactly where their investigation ended, and work the response-authority split between what Arctic Wolf does and what the MSP must do.

Auvik Network Monitoring

An Auvik network-monitoring alert landed — separate a device-down from an interface-down from a config-change, use the topology map to see cascades before chasing symptoms, and feed chronic noise into an alert-tuning loop. Verify against Auvik's current documentation.

Axcient Backup Alerts

An Axcient x360Recover alert needs triage — distinguish appliance-based vs Direct-to-Cloud failure families, verify retention is doing what the client's design says, and state the last recoverable point.

Bitdefender GravityZone

A Bitdefender GravityZone alert landed — identify which detection layer fired (on-access AV, behavioral ATC, HyperDetect, network attack, EDR incident), read Risk Analytics findings correctly, and use quarantine/rollback options without over- or under-trusting them.

Bitwarden Business

A Bitwarden (Teams/Enterprise) rollout or admin ticket arrived — organization/collection structure, group-based sharing, account recovery (admin reset / trusted-device), and offboarding. Covers self-hosted caveats. Verify against Bitwarden's current documentation.

Blackpoint SOC Response

A Blackpoint MDR SOC call or alert arrived — their analysts often contained already (host isolated, account disabled). Confirm what was done, work what remains, and merge the companion ticket storm.

Cork Protection Posture

A Cork cyber-warranty posture signal landed — read which required control slipped, understand that the signal is a warranty-eligibility gap (not an active incident), and drive it back into compliance before coverage lapses.

Cove Data Protection Alerts

An N-able Cove Data Protection backup ticket arrived — classify the failure family, verify recoverability rather than assuming it, and keep archive/retention sessions straight from standard sessions. Verify against N-able's current Cove documentation.

CrowdStrike Falcon Alerts

A CrowdStrike Falcon detection or incident landed — parse the detection anatomy, decide whether Network Contain is warranted, and know when mass simultaneous endpoint failures mean a vendor-side problem rather than an attack.

Datto BCDR Verification

A Datto BCDR alert needs working — screenshot-verification failure, local backup vs off-site (cloud) sync lag, or virtualization-test cadence questions. Separate "backup ran" from "backup boots" and state the real recovery position.

Defender M365 Alerts

A Microsoft Defender / Entra alert arrived — Safe Links or Safe Attachments detonation, suspicious inbox rule, or risky sign-in. Identify the alert family, correlate it to its Defender incident, and route to the right runbook with portal paths for the tech.

Defender Quarantine Ops

A Microsoft 365 quarantine item needs review or a user requested a release — apply the quarantine-release-request discipline with Defender-specific portal paths, verdict types, and release mechanics.

DNS Filtering Alerts

A DNS-filter block event or category complaint arrived (Cisco Umbrella, DNSFilter, or similar) — separate security blocks (possible infection signal) from category blocks (policy), and keep bypass/category-change discipline.

Duo MFA Anomalies

A Duo event needs working — a user-reported fraudulent push, a push-fatigue pattern, a device re-enrollment, or a bypass-code request. Identity verification first; bypass codes are time-boxed, logged, and never casual.

ESET PROTECT

An ESET PROTECT detection or protection-status alert landed — triage by detection engine, interpret LiveGuard sandbox verdicts (including files held pending analysis), and recognize when a "protection disabled" alarm is really a policy conflict.

Huntress EDR Incident

A Huntress EDR incident report arrived — foothold, persistence, or active threat on an endpoint. Read what Huntress already did (isolation, remediation steps), execute what remains, and verify before closing.

Huntress ITDR Alerts

A Huntress managed-identity (ITDR) report landed — unwanted access, rogue app, or mail-rule anomaly. Parse the Huntress report anatomy, work the verify-with-user ladder, and drive the Huntress remediation-approval flow to a documented outcome.

IRONSCALES Phishing

An IRONSCALES incident or user banner-report landed — read the mailbox-level detection and classification, act on the automated remediation across affected mailboxes, and triage employee reports without training the model wrong.

Kaseya Dark Web Monitoring

A Dark Web ID (Kaseya) compromise alert arrived — parse the vendor's alert anatomy (source, date, data classes), then run the dark-web-alert-lifecycle age/notify logic. Same hard no-cracking policy.

Keeper Password Manager

A Keeper Security rollout or admin ticket arrived — vault/record and shared-folder structure, role-enforced sharing discipline, break-glass access, and offboarding vault transfer via Account Transfer. Verify against Keeper's current documentation.

KnowBe4 Awareness & PhishER

Coordinate a KnowBe4 program — security-awareness training campaigns and phishing simulations — and triage user-reported emails flowing in through PhishER / the Phish Alert Button, keeping simulation reports from colliding with real-phish investigation. Verify against KnowBe4's current documentation.

LastPass Migration

A client conversation or ticket about LastPass in the post-breach era — run the migration-away runbook (export, import, rotate everything, decommission) and handle the breach-history discussion with facts only, dates verified against the vendor's own disclosures. Verify all breach details against current public records.

M365 SaaS Backup

A SaaS backup ticket arrived (M365/Google Workspace backup products generically) — a point-in-time restore request, a protection-scope/license reconciliation, or a job failure. Verify authorization before restores and reconcile protected seats against real users.

Mimecast Email Gateway

A Mimecast event needs working — a held message release request, a URL Protect click alert, or an impersonation-protect hit. Read the hold reason, apply release discipline, and treat allowed clicks as live incidents.

NinjaOne Alert Types

A NinjaOne-native condition/threshold alert landed — classify the alert type (offline, resource threshold, service, patch, hardware/health, security), read live device state with the real NinjaOne tools, and route each class to its runbook with a deep-link handoff.

Proofpoint Email Security

A Proofpoint event needs working — a TAP click or attachment-sandbox alert, a quarantine-digest release request, or VAP-driven prioritization. Read permitted-vs-blocked clicks correctly and keep release discipline.

SaaS Alerts MDR

A SaaS Alerts event landed — a login anomaly, mail-rule creation, file-activity spike, or privilege change in a client's M365/Google tenant. Triage it as identity-plane EDR: verify, contain, scope — and check what the Respond automation already did.

ScreenConnect Access

A ScreenConnect / ConnectWise Control access problem landed — troubleshoot unattended-agent health and session connectivity from the symptom and docs, and hand the technician into the console. It is a remote-access tool, not a script-execution surface.

Security Vendor Generic

A security alert arrived from a product with no dedicated vendor runbook — extract the alert anatomy, map its severity to the desk's tiers, separate containment-already-done from containment-needed, and build a vendor escalation package.

SentinelOne Ranger

A SentinelOne Ranger network-discovery finding landed — read the rogue/unmanaged-device signal, tell a genuinely unknown asset from known-but-unmanaged infrastructure, and drive it to identify-then-manage without blind network action.

SentinelOne Threat Verdict

A SentinelOne threat detection needs triage — read the static vs behavioral engine verdict and mitigation status, direct kill/quarantine/rollback/disconnect decisions, and hold the line on exclusion requests.

Sophos Endpoint Alerts

A Sophos Central endpoint alert needs triage — read the health status and cleanup result, handle tamper protection correctly, and verify cleanup actually completed before closing.

Synology NAS Alerts

A Synology NAS alert needs working — degraded RAID/storage pool, disk health warnings, volume nearly full, or DSM update decisions. Treat a degraded array as one failure from data loss and keep disk-replacement discipline.

TeamViewer Access

A TeamViewer remote-access problem landed — troubleshoot host/agent health, unattended access, and session connectivity from the symptom and docs, watch for the commercial-use-detected flag, and hand the technician into the console. Access tool, not a script surface.

ThreatDown Malwarebytes

A ThreatDown (Malwarebytes) detection landed — triage by detection class (malware vs PUP vs PUM vs exploit), and run the remediation-verification pass that the product's "remediated" status does not do for you.

ThreatLocker Allowlisting

A ThreatLocker approval request, elevation request, or mode question arrived — triage the daily allowlisting approvals safely (the core workload), keep Learning vs Secured mode straight, and handle Elevation Control and Storage Control requests without eroding zero-trust. Verify against ThreatLocker's current documentation.

Todyl Platform

A Todyl alert landed — first determine which plane it came from (SASE network, endpoint EDR, or identity/SIEM detection), because the same platform emits all three and each demands a different runbook.

Trend Micro Worry-Free

A Trend Micro Worry-Free alert landed — triage by detection engine (signature, predictive ML, behavior monitoring, web reputation), work within the MSP-tier console model, and know when a client is actually on Apex Central / Vision One instead.

Veeam Job Failures

A Veeam backup job failed or warned — classify the failure into the Veeam taxonomy (VSS, credentials, repository, network), apply retry discipline instead of blind reruns, and state the client's real exposure via the last successful restore point.

WatchGuard Firewall Alerts

A WatchGuard event needs triage — a Firebox offline in WatchGuard Cloud, AuthPoint MFA push/token trouble, or mobile-VPN authentication failures. Separate connectivity from compromise and keep the AuthPoint identity discipline.

Webroot Legacy AV

A Webroot (or similar legacy signature-AV) detection needs handling — work it with honest acknowledgment of the thin telemetry, and frame the modern-EDR migration conversation on facts, not fear.