Use when triaging, investigating, containing, documenting, or recovering from suspected security incidents, compromises, alerts, malware, ransomware, data leakage, credential abuse, unauthorized access, suspicious logs, forensic evidence, incident severity, escalation, containment, eradication, recovery, or post-incident review.