incident-responder

Execute incident response for security events with triage, containment, and forensic investigation.

6|1|Updated Feb 20, 2026
One-click install
npx skills add https://github.com/aviskaar/open-org --skill incident-responder-aviskaar
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: incident-responder
Source: https://github.com/aviskaar/open-org/tree/main/skills/incident-responder
Command: npx skills add https://github.com/aviskaar/open-org --skill incident-responder-aviskaar

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

This Skill provides a structured and comprehensive approach to managing security incidents, from initial triage and containment to forensic investigation, regulatory notification, and post-incident improvement.

Core Features & Use Cases

  • Incident Triage & Classification: Quickly assess and categorize incidents based on severity.
  • Containment Playbooks: Offers specific strategies for ransomware, data exfiltration, and insider threats.
  • Forensic Investigation Standards: Guides evidence collection and analysis with chain-of-custody requirements.
  • Regulatory Notification: Details obligations under various data privacy laws.
  • Change & Problem Management Integration: Aligns incident response with ITIL best practices.
  • Post-Incident Reviews: Facilitates blameless reviews to drive continuous improvement.

Quick Start

Use the incident-responder skill to initiate a P1 ransomware response playbook.

Frequently Asked Questions about incident-responder

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I respond to a ransomware attack and contain the threat?

To respond to ransomware, you need a structured incident response process for rapid containment. This Skill executes specific ransomware playbooks to isolate affected systems, preserve forensic evidence, and prevent further data exfiltration.

What is the best way to conduct a forensic investigation after a security breach?

The best way to conduct a forensic investigation is by following strict chain-of-custody standards. This Skill guides evidence collection and analysis to ensure admissibility, integrating with ITIL problem management for post-incident improvement.

How do I handle regulatory breach notification for data exfiltration?

Handling regulatory breach notification requires meeting specific data privacy obligations. This Skill details notification requirements across various laws, ensuring compliant communication following a suspected data exfiltration event.

Can I use a structured playbook for insider threat investigation and containment?

Yes, you can use structured playbooks for insider threat investigation. This Skill provides specific containment strategies and triage procedures to manage insider threats while preserving necessary forensic evidence.

When do I need ITIL change management integration for incident response?

You need ITIL change management integration during incident response when implementing containment fixes or permanent resolutions. This Skill aligns active security incident handling with problem and change management processes for continuous improvement.