Live
Black Hat USADark ReadingBlack Hat AsiaAI BusinessHow Disney Imagineers are using AI and robotics to reshape the company’s theme parksFast Company TechGoogle Home’s latest update makes Gemini better at understanding your commandsThe VergeArtemis II: Why our return to the moon took so longFast Company TechRising gas prices are good news for EV sales, for nowThe VergeMy two Raspberry Pi boards cost as much as a laptop now - and AI is to blameZDNet Big DataQwen 3.6 Plus Just Dropped and it Huge!AI YouTube Channel 31Dan Pratl believes the credibility economy is coming and it will redefine value in the age of AIThe Next Web NeuralQuálitas Scales Agentic AI for End-to-End Claims Resolution With SoundHound AI’s AI Agent Platform - Yahoo FinanceGNews AI agenticOfcom studies show more caution over social media in 2025 but more widespread use of AI - TelecompaperGNews AI UKPost Quantum Cryptography - ComputerphileComputerphile YTExclusive: Anvil Robotics Raises $5.5M to Build ‘Legos for Robots’ Platform For Physical AI Teams - Crunchbase NewsGNews AI manufacturingPickNik Robotics gives MoveIt Pro 9.0 enhanced perception-to-motion, teleop capabilitiesRobotics Business ReviewBlack Hat USADark ReadingBlack Hat AsiaAI BusinessHow Disney Imagineers are using AI and robotics to reshape the company’s theme parksFast Company TechGoogle Home’s latest update makes Gemini better at understanding your commandsThe VergeArtemis II: Why our return to the moon took so longFast Company TechRising gas prices are good news for EV sales, for nowThe VergeMy two Raspberry Pi boards cost as much as a laptop now - and AI is to blameZDNet Big DataQwen 3.6 Plus Just Dropped and it Huge!AI YouTube Channel 31Dan Pratl believes the credibility economy is coming and it will redefine value in the age of AIThe Next Web NeuralQuálitas Scales Agentic AI for End-to-End Claims Resolution With SoundHound AI’s AI Agent Platform - Yahoo FinanceGNews AI agenticOfcom studies show more caution over social media in 2025 but more widespread use of AI - TelecompaperGNews AI UKPost Quantum Cryptography - ComputerphileComputerphile YTExclusive: Anvil Robotics Raises $5.5M to Build ‘Legos for Robots’ Platform For Physical AI Teams - Crunchbase NewsGNews AI manufacturingPickNik Robotics gives MoveIt Pro 9.0 enhanced perception-to-motion, teleop capabilitiesRobotics Business Review
AI NEWS HUBbyEIGENVECTOREigenvector

Why SOC analysts get inconsistent results from ChatGPT (and how structured workflows fix it)

DEV Communityby gaurav kunduApril 2, 20262 min read0 views
Source Quiz

<p>If you've ever handed a security alert to ChatGPT and gotten a different answer each time — you've hit the real problem.</p> <p>It's not the model. It's the prompt.</p> <p>Most analysts paste an alert and ask "what do you think?" That's like asking a junior analyst to investigate without a runbook. You'll get something back, but the quality depends entirely on how the question was framed.</p> <h2> The real problem: no structure </h2> <p>Experienced SOC analysts don't wing investigations. They follow a process:</p> <ul> <li>Triage the alert</li> <li>Map to MITRE ATT&amp;CK</li> <li>Check for lateral movement</li> <li>Build a containment recommendation</li> <li>Write a ticket summary</li> </ul> <p>The issue is that most AI-assisted workflows skip steps 2–5 and jump straight to "is this ba

If you've ever handed a security alert to ChatGPT and gotten a different answer each time — you've hit the real problem.

It's not the model. It's the prompt.

Most analysts paste an alert and ask "what do you think?" That's like asking a junior analyst to investigate without a runbook. You'll get something back, but the quality depends entirely on how the question was framed.

The real problem: no structure

Experienced SOC analysts don't wing investigations. They follow a process:

  • Triage the alert

  • Map to MITRE ATT&CK

  • Check for lateral movement

  • Build a containment recommendation

  • Write a ticket summary

The issue is that most AI-assisted workflows skip steps 2–5 and jump straight to "is this bad?"

What I built

I spent time building SOC.Workflows — a free collection of structured investigation workflows for SOC analysts. Each workflow breaks an investigation into 4 steps, with specific prompts for each step, designed to run in ChatGPT or Claude.

Current workflows:

  • Phishing Email Investigation

  • AWS VPC Flow Log Analysis

  • PowerShell & Script Analysis

  • Credential Dumping Investigation

  • Ransomware Triage

  • Identity Compromise Investigation

  • URL & Domain Analysis

  • SOC Alert Triage

  • Explain This Alert

How it works

  • Pick a workflow matching your alert type

  • Copy the workflow prompt

  • Paste into ChatGPT or Claude

  • Get structured, step-by-step analysis

No login. No setup. No API keys.

Why structure matters

When I ran the same phishing alert through an unstructured prompt vs. the structured workflow, the difference was clear:

Unstructured: "This looks like a phishing email. Check the sender domain."

Structured: SPF/DKIM validation → header analysis → sender reputation → verdict with risk score → recommended response actions

Same model. Completely different output quality.

Try it

If you work in a SOC or do blue team work, I'd love feedback on which investigation types are missing.

👉 socworkflows.com — free, no login required

Was this article helpful?

Sign in to highlight and annotate this article

AI
Ask AI about this article
Powered by Eigenvector · full article context loaded
Ready

Conversation starters

Ask anything about this article…

Daily AI Digest

Get the top 5 AI stories delivered to your inbox every morning.

Knowledge Map

Knowledge Map
TopicsEntitiesSource
Why SOC ana…claudemodelanalysischatgptDEV Communi…

Connected Articles — Knowledge Graph

This article is connected to other articles through shared AI topics and tags.

Knowledge Graph100 articles · 164 connections
Scroll to zoom · drag to pan · click to open

Discussion

Sign in to join the discussion

No comments yet — be the first to share your thoughts!