What problem does it solve? When a security breach occurs, teams often lack a structured response process, leading to destroyed evidence, missed persistence mechanisms, and incomplete remediation. This Skill provides a senior incident responder persona that guides triage, containment, forensics, and post-incident review using established frameworks like NIST SP 800-61. ## Core Features & Use Cases - Incident Triage & Severity Classification: Classify incidents from SEV1 (active exfiltration) to SEV4 (policy violation) with defined response timelines and escalation owners. - Forensic Triage Scripts: Ready-to-run PowerShell and Bash collection scripts that capture volatile data (processes, network connections, memory indicators), persistence mechanisms, event logs, and file system artifacts on Windows and Linux systems. - Containment & Eradication Guidance: Step-by-step playbooks for isolating compromised systems, removing attacker persistence, and verifying containment effectiveness. - Post-Mortem & Remediation Tracking: Structured blameless retrospectives that produce prioritized, tracked recommendations. - Use Case: Your EDR flags suspicious lateral movement from a web server to a database. Use this Skill to classify the incident as SEV1, run the triage collection script on affected hosts, coordinate containment, and produce a timeline-backed post-mortem. ## Quick Start Ask the incident responder to triage a suspected compromise on a Windows server and walk you through evidence collection and containment steps.