What problem does it solve?
It provides structured, framework-referenced guidance for isolating an ongoing incident and limiting further damage while balancing operational disruption.
Core Features & Use Cases
- NIST SP 800-61 Rev 2 containment decisioning: Chooses containment actions based on damage potential, evidence preservation, service availability, resources, and duration.
- MITRE ATT&CK technique mapping: Produces countermeasures tied to the attacker’s observed TTPs (initial access, lateral movement, command and control, persistence, and destructive malware).
- Actionable, auditable output: Produces a containment plan with short-term and long-term actions, validation checklist, business impact assessment, and rollback criteria suitable for SOC and security engineering teams.
- Safety guardrails: Emphasizes planning only (human execution for containment actions) and avoids leaking sensitive attacker details.
Quick Start
Ask an AI coding agent to create a containment plan for a confirmed incident that requires network isolation and credential revocation, and include the relevant incident ID and targets.