What problem does it solve?
This Skill provides structured containment playbooks to isolate threats during active security incidents, enabling responders to rapidly contain threats across multiple layers.
Core Features & Use Cases
- Network Containment: Host isolation, firewall controls, DNS sinkholing, and segmentation.
- Endpoint Containment: EDR-based quarantine, process and service actions, memory preservation.
- Identity Containment: Account disablement, session termination, password reset workflows.
- Cloud Containment: IAM revocation, resource isolation, API key rotation, and access governance.
- Application Containment: WAF rules, rate limiting, and service lockdown.
- Playbook Management: Track actions, document decisions, and generate reports for incident review.
Quick Start
Create and run a containment playbook by using the containment utilities to instantiate actions from NetworkContainment, EndpointContainment, IdentityContainment, CloudContainment, and ApplicationContainment, then compile a final report.