agency-incident-responder

Perform forensic triage and incident response on Windows and Linux systems.

Updated Jul 23, 2026
One-click install
npx skills add https://github.com/rajyeole6/AI-RECRUITER --skill agency-incident-responder
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: agency-incident-responder
Source: https://github.com/rajyeole6/AI-RECRUITER/tree/main/.agents/skills/security-incident-responder
Command: npx skills add https://github.com/rajyeole6/AI-RECRUITER --skill agency-incident-responder

SYSTEM DOCUMENTATION & REQUIREMENTS

💡 This Skill includes scripts (resource) and references (resource) components.

What problem does it solve?

This skill addresses the critical need for rapid, methodical, and evidence-based response to security breaches, preventing data loss and minimizing operational downtime during active cyberattacks.

Core Features & Use Cases

  • Incident Triage & Classification: Rapidly assesses the severity of security incidents using a standardized framework to prioritize response efforts.
  • Forensic Triage: Executes automated collection of volatile data, persistence mechanisms, and event logs on Windows and Linux systems to preserve evidence.
  • Use Case: When a potential ransomware infection is detected, use this skill to immediately capture memory and network state, classify the incident severity, and generate a containment plan to stop lateral movement.

Quick Start

Use the agency-incident-responder skill to perform a forensic triage collection on the suspected compromised Windows server.

Frequently Asked Questions about agency-incident-responder

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I perform digital forensics and incident response after a security breach?

Digital forensics and incident response requires systematic threat triage, evidence preservation, and post-mortem analysis. This skill facilitates rapid assessment, volatile data collection, and containment planning to minimize operational downtime during active cyberattacks.

What is the best way to triage and classify a suspected ransomware infection?

Triage and classification of ransomware requires a standardized framework to assess incident severity and prioritize response efforts. This skill helps rapidly evaluate the threat, capture memory and network state, and generate a containment plan to stop lateral movement.

Does this incident response skill support evidence collection on both Windows and Linux systems?

Yes, incident response evidence collection supports both Windows and Linux systems. The skill executes automated collection of volatile data, persistence mechanisms, and event logs across diverse infrastructure environments to preserve critical forensic evidence.

How do I maintain chain of custody and document incidents according to NIST SP 800-61?

Maintaining chain of custody and incident documentation according to NIST SP 800-61 requires systematic evidence preservation and post-mortem analysis. This skill satisfies technical requirements for standardized incident documentation and response adherence.

Can I use this for threat hunting and detecting lateral movement during an active attack?

Yes, threat hunting and detecting lateral movement during active attacks are supported. The skill provides comprehensive capabilities for investigating security breaches, capturing network state, and generating containment plans to prevent further lateral movement.

What is forensic triage and when do I need to collect volatile data?

Forensic triage is the rapid collection of volatile data, persistence mechanisms, and event logs to preserve evidence. You need it immediately when a breach is detected to prevent data loss and ensure critical system state is captured before it is lost.