blue-ir

Structure evidence and construct chronological timelines for incident response triage.

Updated Jul 30, 2026
One-click install
npx skills add https://github.com/salmanabdurrahman/pi-pentest-agent --skill blue-ir
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: blue-ir
Source: https://github.com/salmanabdurrahman/pi-pentest-agent/tree/main/skills/blue-ir
Command: npx skills add https://github.com/salmanabdurrahman/pi-pentest-agent --skill blue-ir

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

This skill addresses the chaos of security incident response by providing a structured, evidence-based framework to triage alerts, build accurate timelines, and coordinate containment decisions without manual overhead.

Core Features & Use Cases

  • Evidence-Backed Timeline Construction: Automatically organizes logs and artifacts into a chronological, verified timeline of events.
  • Scope of Compromise Assessment: Systematically identifies the blast radius, including affected systems, accounts, and data exposure levels.
  • Containment Guidance: Provides structured, risk-aware recommendations for containment actions like network isolation or credential rotation, ensuring operational impact is assessed before execution.

Quick Start

Use the blue-ir skill to analyze the provided incident ticket and build a preliminary timeline of events based on the attached log extracts.

Frequently Asked Questions about blue-ir

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I build an incident response timeline from security logs?

To build an incident response timeline, the skill automatically organizes pre-collected logs and redacted artifacts into a chronological, verified sequence of events. This structures your evidence and clarifies the progression of a security incident without manual overhead.

What is the best way to assess the scope of a security compromise?

Assessing the scope of a security compromise involves systematically identifying the blast radius, including affected systems, compromised accounts, and data exposure levels. This skill evaluates these factors to determine the full extent of an incident.

How do I get guidance on containment decisions during incident triage?

To get guidance on containment decisions during incident triage, the skill provides structured, risk-aware recommendations for actions like network isolation or credential rotation. It ensures operational impact is assessed before execution to support non-destructive incident management.

Does incident response triage work with pre-collected artifacts?

Incident response triage operates strictly with pre-collected, redacted artifacts. It requires this prepared evidence to construct timelines and guide forensic preservation, ensuring safe handling of security data within defensive workflows.

Why do I need authorization gates for incident response?

You need authorization gates for incident response to ensure strict adherence to policy validation. This guarantees safe, non-destructive incident management by enforcing containment decisions and forensic preservation only after proper approval.