Use when a task needs the judgment of an Information Security Analyst — triaging and investigating a security alert or suspected intrusion, designing or tuning detection rules and access controls, running incident response through containment/eradication/recovery, prioritizing a vulnerability-patching backlog, or reconstructing an attack timeline across compromised hosts.