emergency-response

Orchestrate incident response workflows across detection, containment, eradication, and recovery.

83|8|Updated May 6, 2026
One-click install
npx skills add https://github.com/Q16G/aster --skill emergency-response-q16g
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: emergency-response
Source: https://github.com/Q16G/aster/tree/main/skills/host-defense/emergency-response
Command: npx skills add https://github.com/Q16G/aster --skill emergency-response-q16g

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

Emergency incident management often lacks a consistent, repeatable process for detecting, containing, eradicating, recovering from security events, and collecting evidence for audits. This skill provides a structured workflow to coordinate responders, preserve evidence, and reduce dwell time.

Core Features & Use Cases

  • Standardized PICERL-based incident response workflow (Preparation, Identification, Containment, Eradication, Recovery, Lessons Learned) for fast, repeatable handling.
  • Forensics-oriented evidence handling, logging, and reporting to support investigations and compliance.
  • Playbook-style guidance for security operations teams during real incidents and simulated exercises.

Quick Start

Provide a step-by-step incident response plan for a security event, including containment, eradication, recovery, and lessons learned.

Frequently Asked Questions about emergency-response

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
What is a standardized incident response playbook for security operations?

A standardized incident response playbook provides structured, repeatable steps for security operations, covering detection, containment, eradication, and recovery. It applies the PICERL workflow to coordinate responders, preserve forensic evidence, and generate incident reports.

How do I handle forensic evidence collection during an active security incident?

Forensic evidence collection during a security incident requires structured handling and logging to preserve data for audits. This skill provides guidance for security operations teams to coordinate evidence collection, maintain logs, and generate reports supporting investigations.

Can I use this incident response workflow for simulated security exercises?

Yes, this incident response workflow supports both real security events and simulated exercises. Security operations teams can apply the playbook-style guidance to practice standardized PICERL steps, from preparation and identification through containment, eradication, recovery, and lessons learned.

What is the best way to orchestrate emergency response across detection and recovery?

The best way to orchestrate emergency response is using a structured workflow that connects detection, containment, eradication, and recovery phases. This approach ensures consistent role assignments, evidence handling, and outputs such as incident reports and IOCs for security operations centers.

Does this incident response skill assign roles and output IOCs for forensics investigations?

Yes, this incident response skill requires structured role assignments and outputs including incident reports and IOCs. It is designed for security operations centers, incident response teams, and forensics investigations where standardized playbooks and evidence handling are required.

Why do I need a PICERL-based workflow for emergency incident management?

You need a PICERL-based workflow for emergency incident management because it provides a consistent, repeatable process for handling security events. This structured approach coordinates responders, preserves evidence for compliance, and reduces attacker dwell time across all incident phases.