---
title: "Run AI-assisted security triage with role-based SOC runbooks from ai-runbooks"
description: "Use ai-runbooks to give AI assistants role-specific SOC personas, investigation steps, and incident-response procedures for structured security triage."
verification: "security_reviewed"
source: "https://github.com/dandye/ai-runbooks"
author: "Dan Dye"
publisher_type: "individual"
category:
  - "Runbooks & Diagnostics"
framework:
  - "Multi-Framework"
tool_ecosystem:
  github_repo: "dandye/ai-runbooks"
  github_stars: 96
---

# Run AI-assisted security triage with role-based SOC runbooks from ai-runbooks

Use ai-runbooks to give AI assistants role-specific SOC personas, investigation steps, and incident-response procedures for structured security triage.

## Prerequisites

Git repository checkout, a supported AI assistant configuration directory, security operations context

## Installation

Choose whichever fits your setup:

1. Copy this skill folder into your local skills directory.
2. Clone the repo and symlink or copy the skill into your agent workspace.
3. Add the repo as a git submodule if you manage shared skills centrally.
4. Install it through your internal provisioning or packaging workflow.
5. Download the folder directly from GitHub and place it in your skills collection.

Install command or upstream instructions:

```
Clone the repository, verify the rules_bank symlinks for the supported assistant directories, then load the relevant persona and runbook content into the assistant workflow as documented in the repository.
```

## Documentation

- https://github.com/dandye/ai-runbooks

## Source

- [Agent Skill Exchange](https://agentskillexchange.com/skills/run-ai-assisted-security-triage-with-role-based-soc-runbooks-from-ai-runbooks/)
