Incident Response Planner
$2.99OfficialDesign incident response playbooks: detection triggers, severity classification, containment, eradication, and communication.
What you get
- โ10-step procedure
- โ6 pitfalls to avoid
- โInstalls into 6 tools
- Version
- v1 โ
- Last updated
- today
- Length
- 5 min read
- Requires
- Best with a strong model (Claude Sonnet 4)
Works in: Claude Code, Codex, Cline, opencode, OpenClaw, Hermes ยท Handles multi-file projects
Preview
When to use
Use this skill to author or revise incident response playbooks: defining how a specific class of incident (ransomware, credential compromise, data exfiltration, misconfiguration, insider threat, supply-chain compromise) is detected, triaged, contained, eradicated, and communicated. It is for preparedness work, not for live incident command โ though the playbooks it produces are the runbook a responder follows under pressure. Align with NIST SP 800-61r2 and your existing SOC tooling.
Inputs to gather
- Incident class the playbook addresses (e.g., business-email compromise, ransomware, public-data exposure).
- Detection sources: SIEM rules, EDR alerts, WAF, cloud audit log
โฆ
๐ Buy once ($2.99) to unlock the full playbook, download it, and install it in every tool you use.