What problem does it solve?
During a confirmed security breach, responders must stop an active adversary quickly without tipping them off, destroying forensic evidence, or leaving gaps like valid Kerberos tickets that let attackers re-enter. This Skill provides a structured containment workflow covering scoping, short-term and long-term containment, validation, and evidence preservation.
Core Features & Use Cases
- Coordinated Containment Execution: Implements network isolation via EDR, C2 blocking and sinkholing, credential revocation, and KRBTGT double-reset procedures in one coordinated action.
- Containment Validation: Verifies that C2 beacons have ceased, disabled accounts produce only failure events, and isolated hosts are unreachable from adjacent subnets.
- Evidence Preservation: Captures memory dumps, volatile data, and event logs before remediation to maintain chain of custody.
- Use Case: When ransomware is spreading via SMB using a compromised service account, use this Skill to isolate file servers, disable the account, block SMB between VLANs, and preserve memory evidence before restoration.
Quick Start
Use the containing-active-breach skill to build a containment plan for an active intrusion involving five compromised hosts and a compromised domain admin account.