What problem does it solve? When a security breach occurs, teams often lack a structured playbook for triaging alerts, preserving volatile evidence, reconstructing attack chains, and coordinating containment across hosts, cloud, and containers. This Skill provides a complete incident response methodology so responders act quickly and consistently instead of improvising under pressure. ## Core Features & Use Cases - Six-Phase Response Framework: Implements NIST SP 800-61r3 (preparation through post-incident) with severity grading (P0-P4), golden-hour timelines, and RACI coordination. - Deep Forensics Coverage: Provides concrete commands for Windows/Linux memory capture, Volatility 3 analysis, KAPE triage, fileless attack hunting, and evidence chain-of-custody handling. - Specialized Scenarios: Covers ransomware response, cloud (AWS/Azure/GCP) and Kubernetes incident handling, hypothesis-driven threat hunting, and LLM security incident response (prompt injection, tool poisoning). - Use Case: An EDR alert shows suspicious PowerShell execution on a database server at 2 AM. Use this Skill to grade the incident, capture memory and logs in the correct volatility order, map findings to MITRE ATT&CK, contain the host, and produce a post-incident report. ## Quick Start Ask the AI to walk you through responding to a confirmed intrusion on a Windows server, starting with evidence collection and containment steps.