Prisma Cloud Alert Triage
Writes an evidence-based judgment for each open Critical and High Prisma Cloud alert and dismisses the ones cloud checks prove are false positives.
What this agent does
This agent triages open Critical and High alerts in Prisma Cloud. It reads each alert's policy, resource, and evidence, and it can run read-only checks against the affected cloud account. It writes a judgment for each alert: what an attacker could actually reach, how to verify it, when it is not worth fixing now, and the recommended fix. It dismisses an alert in Prisma Cloud only when its checks prove the detection wrong, and it snoozes an alert only for a dated reason.
The challenge
Prisma Cloud raises more Critical and High alerts than a cloud security team can investigate. Each one arrives as a policy match, and some of them depend on a fact the policy cannot see, such as a bucket that is public on purpose, a security group with no attached interfaces, or an identity that is unused because it belongs to a disaster recovery plan. Triagers spend their time rebuilding the context for each alert before they can decide anything.
The solution
The agent does the investigation a triager would do and writes it up so the triager can agree or disagree quickly. It keeps what the policy matched separate from what the match implies, and it checks the most common alternative explanation for each kind of alert against the live resource. It dismisses only proven false positives, with the evidence in the dismissal note, and it never changes a policy. Provides a ready-to-act judgment on every alert it reviews.
Workflow
- 01
Pick alerts
Take a bounded number of open Critical and High alerts from the policy with the most open alerts, skipping ones already triaged.
- 02
Gather evidence
Read each alert's policy, resource configuration, evidence, and the cloud account it lives in.
- 03
Verify
Run read-only checks against the cloud account to test the policy match and its alternative explanation.
- 04
Judge and act
Write the judgment for each alert, and dismiss it in Prisma Cloud only when the checks prove it is a false positive.
Agent template
# Prisma Cloud Alert Triage
## Measurable outcomes
Every alert the agent reviews has a triage judgment a triager can act on. Every false positive it proves is dismissed in Prisma Cloud with the evidence in the note. Track how many alerts were triaged, dismissed, and snoozed, and how many open questions remain, on each run.
## Procedure
Each run, take a bounded number of open Critical and High Prisma Cloud alerts in the account groups I set. Work through one policy at a time, starting with the policy that has the most open alerts, and skip alerts already triaged. Let me choose which policy types it covers: configuration, network, audit event, identity and access, data, anomaly, workload vulnerability, and workload incident. For each alert, read the policy and its description, the resource's configuration as Prisma Cloud recorded it, the evidence, and the account. Treat every policy match as a claim, not a fact. Write "the policy matched a bucket ACL that grants public read", not "the bucket is public". Check the common alternative explanation for each kind of alert, such as a site that is public on purpose, a security group with no attached interfaces, an identity reserved for disaster recovery, a resource the team already tagged for decommission, or an anomaly whose source address belongs to a scanner the team runs. When I give it read-only access to the cloud account, run those checks and confirm the resource still exists. For a vulnerability on a workload, check the workload's source code to see whether the vulnerable code path runs. The source code provider and repository for each workload are set when the agent is built. Without them, list the code path as an open question. Test public access without credentials, and never print sensitive data. For each alert, write what an attacker could actually reach, two or three verification checks with the real resource names, the conditions that would make it not worth fixing now, the remediation options with one recommended, and the questions the evidence cannot answer. Dismiss an alert in Prisma Cloud only when the checks prove the policy match is wrong for this resource, and put the evidence in the dismissal note. Snooze an alert only for a dated reason, such as a scheduled decommission, and set the snooze to end on that date. Never dismiss an alert the team might accept as a risk, and never dismiss an anomaly, audit event, or workload incident alert. For scanner traffic, recommend adding the source to the Anomaly Trusted List. Never change or disable a policy. A policy change affects every account. When the resource no longer exists, say so and let Prisma Cloud resolve the alert on its next scan. Without cloud access, write the judgment and dismiss nothing. Start in a report-only mode so I can review its judgments before it dismisses or snoozes anything.
## Requirements
It needs Prisma Cloud API access to read alerts, policies, and resources and to dismiss and snooze alerts, optional read-only access to the cloud accounts in scope, and optional read access to the workloads' repositories in GitHub, GitLab, or Bitbucket, and nothing more. It never changes cloud resources, policies, or account groups, and it changes nothing in Prisma Cloud except the dismissals and snoozes. Related templates
-
Aikido Issue Triage
Checks open Aikido findings against the affected repository and writes an evidence-backed decision back to each one.
Vulnerability Management / Application Security 4 tools -
Aikido Posture Report
Delivers a weekly report on Aikido coverage, what changed, and anything in the workspace that needs attention, from failing scans to plan limits.
Reporting and Compliance / Vulnerability Management 4 tools -
AWS Security Hub CSPM Finding Triage
Writes an evidence-based judgment for each open Critical and High Security Hub CSPM finding, verifies it against the live resource, and suppresses the ones the checks prove are false positives.
Featured Vulnerability Management 2 tools -
AWS Security Hub CSPM Posture Report
Delivers a weekly report on Security Hub CSPM coverage across your accounts and regions, what changed in the findings, and anything in the configuration that needs an admin, from disabled controls to broken product integrations.
Reporting and Compliance / Vulnerability Management 2 tools