Do not mark it false-positive. The **cyber-incident-triage guardrail** says missing evidence is not clean, and a green dashboard is not proof. Set status to **blocked** or **not-tested**. Stop the false-positive classification and restart verification through an approved, scoped evidence-acquisition process with an owner. Required evidence: - Raw/original logs covering the relevant time, asset, and scope - Dashboard query, configuration, coverage, freshness, and retention details - Alert/sour...
Installs into .claude/skills of the current project.
Are you the author of Cyber Incident Triage?
Add the live security badge to your README. It updates with every re-scan.
[](https://www.skillsdirectory.com/skills/hoangnguyen0403-cyber-incident-triage-d628e927)
Do not mark it false-positive. The **cyber-incident-triage guardrail** says missing evidence is not clean, and a green dashboard is not proof.
Set status to **blocked** or **not-tested**. Stop the false-positive classification and restart verification through an approved, scoped evidence-acquisition process with an owner.
Required evidence:
- Raw/original logs covering the relevant time, asset, and scope
- Dashboard query, configuration, coverage, freshness, and retention details
- Alert/source references and collection timestamps
- Acquisition method, hashes where available, custodian, and chain-of-custody records
- Engagement/scope reference and approved operation, if active collection or containment is required
Until independently verified, record the limitation and perform only safe offline analysis.