incident-responder

Coordinate incident response workflows across detection, containment, eradication, and recovery.

Updated Nov 5, 2025
One-click install
npx skills add https://github.com/tekgrunt/boot-test --skill incident-responder-tekgrunt
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: incident-responder
Source: https://github.com/tekgrunt/boot-test/tree/main/.claude-plugin/plugins/limacharlie-skills/skills/incident-responder
Command: npx skills add https://github.com/tekgrunt/boot-test --skill incident-responder-tekgrunt

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

Streamlines and standardizes incident response by guiding users through detection, investigation, containment, eradication, and recovery workflows within LimaCharlie.

Core Features & Use Cases

  • Instant deployment and real-time response using LimaCharlie primitives (D&R rules, LCQL, artifact collection, and sensor commands).
  • End-to-end IR lifecycle support: detection, investigation, containment, eradication, recovery, and lessons learned.
  • Structured workflows with investigation IDs, artifact collection, and centralized reporting for forensics and post-incident governance.

Quick Start

Initiate an end-to-end incident response workflow for a detected security incident.

Frequently Asked Questions about incident-responder

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I coordinate an end-to-end incident response workflow across endpoints, networks, and cloud environments?

Coordinate end-to-end incident response workflows by guiding teams through detection, investigation, containment, eradication, and recovery using structured investigation IDs and automated D&R rules across endpoints, networks, and cloud environments.

Can I automate forensic artifact collection during a security investigation?

Automate forensic artifact collection during security investigations by applying LimaCharlie sensor commands and frontmatter-driven guidance to collect, track, and centralize artifacts using unique investigation IDs.

How does LCQL support threat hunting and incident remediation?

LCQL supports threat hunting and incident remediation by enabling structured queries across sensors to detect threats, investigate timelines, and drive automated responses within the incident response lifecycle.

What's the best way to standardize post-incident recovery and lessons learned reporting?

Standardize post-incident recovery and lessons learned reporting by leveraging centralized reporting, structured investigation workflows, and frontmatter-driven guidance to document remediation actions and governance outcomes.

Does this incident response workflow require LimaCharlie D&R rules to function?

The incident response workflow leverages LimaCharlie D&R rules, LCQL queries, and sensor commands as core primitives to drive automated detection, containment, and eradication actions across the environment.

How do I initiate a rapid incident response workflow for a detected security incident?

Initiate a rapid incident response workflow for a detected security incident by deploying detection rules, assigning an investigation ID, collecting artifacts, and executing containment and eradication steps across affected endpoints and cloud environments.