incident-responder

Automate CSIRT-style incident response workflows with evidence handling and regulatory preparation.

7|1|Updated May 19, 2026
One-click install
npx skills add https://github.com/daemon-blockint-tech/Agentic-Enteprises-Skill --skill incident-responder-daemon-blockint-tech
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: incident-responder
Source: https://github.com/daemon-blockint-tech/Agentic-Enteprises-Skill/tree/main/incident-responder
Command: npx skills add https://github.com/daemon-blockint-tech/Agentic-Enteprises-Skill --skill incident-responder-daemon-blockint-tech

SYSTEM DOCUMENTATION & REQUIREMENTS

💡 This Skill includes references (resource) components.

What problem does it solve?

Guides CSIRT-style incident response—declaring incidents, scoping and severity, timeline reconstruction, evidence preservation, containment/eradication/recovery coordination, stakeholder communication templates, post-incident review, and regulatory preparation.

Core Features & Use Cases

  • Declaration and severity: classify incidents and assign scope and urgency.
  • Timeline reconstruction and evidence handling: build auditable timelines with custody tracking.
  • Containment, eradication, and recovery coordination: coordinate actions across teams with clear ownership.
  • Stakeholder communications and regulatory prep: generate internal/external updates and regulatory fact packs.
  • Post-incident review: capture lessons learned and improvement actions.

Quick Start

Initiate a CSIRT-style incident response workflow for a suspected breach and generate a timeline, containment plan, and stakeholder updates.

Frequently Asked Questions about incident-responder

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I coordinate CSIRT-style incident response workflows for a suspected security breach?

CSIRT-style incident response workflows are automated by guiding you through declaration, severity labeling, timeline reconstruction, evidence preservation, and containment coordination. The workflow applies strict chain-of-custody handling and stakeholder communication generation from start to finish.

What is the best way to reconstruct an incident timeline with proper chain-of-custody for forensic evidence?

Incident timeline reconstruction is automated by building auditable timelines alongside strict evidence handling and chain-of-custody tracking. This ensures your forensic evidence maintains legal admissibility throughout the incident response process.

How do I prepare regulatory notification fact packs after a security incident?

Regulatory notification preparation is handled by generating stakeholder communication templates and regulatory fact packs based on the reconstructed incident timeline and preserved evidence. This streamlines your compliance reporting obligations following a breach.

Does this incident response workflow handle post-incident review and lessons learned documentation?

Post-incident review is fully supported by capturing lessons learned and generating improvement actions after containment, eradication, and recovery coordination are complete. This closes the CSIRT workflow loop with actionable remediation steps.

Can I use this incident response playbook for scoping and severity classification of security incidents?

Incident scoping and severity classification are handled at the declaration stage of the CSIRT workflow, assigning appropriate urgency and scope labels. This establishes the foundational prioritization for all subsequent containment and stakeholder communication actions.