Incident Response Planner

$2.99Official

Design incident response playbooks: detection triggers, severity classification, containment, eradication, and communication.

securityincident-responsesocplaybookssecurity-operationsยท by SkillingMain

What you get

  • โœ“10-step procedure
  • โœ“6 pitfalls to avoid
  • โœ“Installs into 6 tools
Version
v1 โ†’
Last updated
today
Length
5 min read
Requires
Best with a strong model (Claude Sonnet 4)

Works in: Claude Code, Codex, Cline, opencode, OpenClaw, Hermes ยท Handles multi-file projects

Preview

When to use

Use this skill to author or revise incident response playbooks: defining how a specific class of incident (ransomware, credential compromise, data exfiltration, misconfiguration, insider threat, supply-chain compromise) is detected, triaged, contained, eradicated, and communicated. It is for preparedness work, not for live incident command โ€” though the playbooks it produces are the runbook a responder follows under pressure. Align with NIST SP 800-61r2 and your existing SOC tooling.

Inputs to gather

  • Incident class the playbook addresses (e.g., business-email compromise, ransomware, public-data exposure).
  • Detection sources: SIEM rules, EDR alerts, WAF, cloud audit log

โ€ฆ

๐Ÿ”’ Buy once ($2.99) to unlock the full playbook, download it, and install it in every tool you use.