incident-responder

Coordinate incident response for security breaches and operational incidents.

68|6|Updated Apr 16, 2020
One-click install
npx skills add https://github.com/zenobi-us/dotfiles --skill incident-responder-zenobi-us
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: incident-responder
Source: https://github.com/zenobi-us/dotfiles/tree/main/ai/files/skills/experts/infrastructure/incident-responder
Command: npx skills add https://github.com/zenobi-us/dotfiles --skill incident-responder-zenobi-us

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

This Skill guides rapid incident response, evidence preservation, and coordinated recovery to minimize impact and prevent recurrence.

Core Features & Use Cases

  • First-response procedures, containment strategies, and evidence preservation
  • Incident classification, communication, and remediation planning
  • Post-incident analysis, lessons learned, and process improvements

Quick Start

Quick Start: Activate the incident response plan, assign roles, and begin evidence collection with an incident timeline.

Frequently Asked Questions about incident-responder

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I coordinate incident response across multiple teams and tools?

Incident response coordination integrates real-time communication, role assignment, and evidence tracking across PagerDuty, Opsgenie, VictorOps, Slack, and Jira. This Skill orchestrates rapid assessment, containment, and recovery by enforcing structured workflows, continuous documentation, and synchronized notifications to minimize incident impact.

What's the best way to preserve evidence during a security breach or incident?

Evidence preservation maintains an unbroken chain of custody through timestamped documentation and forensic containment procedures. This Skill enforces continuous evidence collection from incident onset through post-incident analysis, preventing tampering and enabling compliance validation and root-cause investigation.

How do I classify and respond to different types of incidents—breaches, outages, performance issues?

Incident classification categorizes security breaches, service outages, performance degradations, data incidents, compliance violations, third-party failures, natural disasters, and human errors into structured response paths. This Skill applies differentiated containment, remediation, and recovery strategies based on incident type and severity.

Can I use incident response management with Slack, Jira, and PagerDuty?

Yes. This Skill integrates natively with PagerDuty, Opsgenie, VictorOps, Slack, Jira, and Statuspage to enable coordinated alerting, role assignment, ticket tracking, and status updates within existing incident management stacks.

What happens after an incident is resolved—how do I capture lessons learned?

Post-incident analysis extracts root causes, documents lessons learned, and drives process improvements to prevent recurrence. This Skill structures retrospectives and remediation planning after containment and recovery are complete.

How quickly can incident response be activated when a breach or outage occurs?

Rapid response activation assigns roles, begins evidence collection, and establishes incident timelines immediately upon detection. This Skill enforces fast first-response procedures and high classification accuracy to contain impact before escalation.