Skip to main content
Everything in the first two lessons — the ticket flow and the data model — turns into daily work here. The Skill Library is your operational bench: prompt-first skills you run from Super Magic to investigate, respond, hand off, and prove the work. These are representative starting points; press ⌘K in Inbox and search any threat or framework to find the rest.

Incident response

The runbooks you reach for when something is actively wrong — each walks the containment, communication, and recovery steps so nothing gets skipped under pressure.

Phishing Triage

Assess a reported email and contain it if it’s malicious.

Account Takeover Runbook

Full response for a compromised account, start to finish.

Business Email Compromise Recovery

Work a BEC from detection through recovery and verification.

Ransomware Response

Contain, communicate, and coordinate recovery.

Session Token Theft Response

Revoke, re-secure, and confirm after stolen-session activity.

Zero-Day Emergency Response

Move fast on an unpatched, actively exploited vulnerability.

Identity and access

The proactive checks that close the gaps attackers use before they get used.

Identity & MFA Health Check

Find identity and MFA gaps across a client tenant.

Global Admin Audit

Review who holds the keys and why.

Impossible Travel Runbook

Work an impossible-travel sign-in to a verdict.

MFA Fatigue Attack Response

Respond to push-bombing and re-secure the account.

Alerts and vendor signal

Turn the alert firehose into triaged, actionable tickets — and cut the noise that buries the real ones.

Security Alert Response

A consistent first-response path for any security alert.

EDR Detection Runbook

Work an endpoint detection from alert to resolution.

DLP Alert Triage

Assess a data-loss alert and decide the response.

Security Noise Tuning

Cut false positives so real alerts stand out.

SOC operations

The rituals and briefs that keep a security desk coherent across shifts and clients.

SOC Shift Handoff

Hand off open incidents and watch items cleanly.

SOC Classification Tree

Classify events consistently, every analyst the same way.

Security Incident Postmortem

Turn an incident into lessons and follow-up actions.

Monthly Security Report

Make a month of security work visible to clients.

Compliance and audit

The evidence, questionnaires, and framework prep that carry your posture through an assessment.

Audit Prep Review

Get ready for an audit without the last-minute scramble.

SOC 2 Evidence Collection

Gather and organize evidence for a SOC 2 cycle.

Security Questionnaire & Vendor DDQ

Answer client security questionnaires and vendor due diligence.

HIPAA Safeguards Checklist

Walk the HIPAA safeguards for a covered client.

NIST CSF Gap Brief

Map a client against the CSF and surface the gaps.

Cyber Insurance Form Prep

Prep an accurate cyber-insurance application.
Every skill is prompt-first — open Super Magic on the relevant ticket and it inherits that ticket’s context, so a runbook starts already knowing the client, contact, and conversation. Investigation stays read-only; any response step still confirms before it runs.

Next

That’s the bench. Head back to the hub for your starter kit and shift ritual, or browse the full library.

Back to your course

Starter kit, SOC ritual, and the FAQ.

Browse the Skill Library

Hundreds of skills — search any threat or framework.