incident-response

Automate evidence collection via shell scripts for forensic analysis.

46|4|Updated Jan 27, 2026
One-click install
npx skills add https://github.com/BagelHole/DevOps-Security-Agent-Skills --skill incident-response-bagelhole
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: incident-response
Source: https://github.com/BagelHole/DevOps-Security-Agent-Skills/tree/main/security/operations/incident-response
Command: npx skills add https://github.com/BagelHole/DevOps-Security-Agent-Skills --skill incident-response-bagelhole

SYSTEM DOCUMENTATION & REQUIREMENTS

💡 This Skill includes scripts (resource) and references (resource) and assets (resource) components.

What problem does it solve?

This Skill provides structured playbooks and tools to effectively manage security incidents, minimizing damage and downtime.

Core Features & Use Cases

  • Incident Response Phases: Follows a clear, six-phase process from preparation to lessons learned.
  • Evidence Collection: Automates the gathering of critical system and network data for forensic analysis.
  • Use Case: When a critical server shows signs of compromise, this Skill can be activated to immediately collect all relevant logs, running processes, and network connections to aid in rapid investigation and containment.

Quick Start

Activate the incident-response skill to collect evidence from the current system.

Frequently Asked Questions about incident-response

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I automate evidence collection during a security incident?

Automate evidence collection during a security incident by activating the Skill to run shell scripts that gather critical system logs, running processes, and network connections for forensic analysis.

What are the standard phases for incident response?

Standard incident response phases follow a structured six-phase process from preparation through lessons learned, guiding teams to detect, contain, eradicate, and recover from security breaches.

How should I handle a compromised server to ensure rapid investigation?

Handle a compromised server for rapid investigation by triggering an incident response playbook that immediately collects relevant logs and network data to aid in containment.

Can I use this framework to classify the severity of a security breach?

Yes, you can use this framework to classify the severity of a security breach, as it provides defined severity classifications to help incident commanders prioritize response efforts.

Does incident response require specific security operations tools to function?

Incident response requires no specific security operations tools to function, as it operates independently without dependencies to automate forensic evidence gathering directly from the current system.