incident-response

Guide structured incident response for server or web compromises.

15|Updated May 12, 2026
One-click install
npx skills add https://github.com/GoldenWing-360/claude-security-skills --skill incident-response-goldenwing-360
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: incident-response
Source: https://github.com/GoldenWing-360/claude-security-skills/tree/main/incident-response
Command: npx skills add https://github.com/GoldenWing-360/claude-security-skills --skill incident-response-goldenwing-360

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

This Skill helps security teams and system administrators run structured incident response procedures to handle server or web compromise scenarios effectively.

Core Features & Use Cases

  • Structured Incident Handling: Guides users through the SANS PICERL phases—from Preparation to Lessons Learned—ensuring comprehensive response.
  • Real-time Guidance: Provides checklists and commands for identifying and containing threats quickly.
  • Use Case: During a suspected server breach, follow the step-by-step procedures to isolate affected systems and gather evidence.

Quick Start

Invoke the incident response skill with details of your suspected breach to receive an actionable plan and command list.

Frequently Asked Questions about incident-response

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
What is the SANS PICERL methodology for incident response?

Structured incident response guides security teams through the SANS PICERL phases, moving from Preparation through Identification, Containment, Eradication, Recovery, and Lessons Learned to comprehensively manage suspected server or web compromises.

How do I contain a suspected server breach quickly?

To contain a suspected server breach, follow structured incident response procedures that provide real-time checklists and commands. This helps quickly isolate affected systems, stop ongoing threats, and gather forensic evidence to minimize damage.

What steps are involved in investigating a web server compromise?

Investigating a web server compromise involves identifying the threat scope, containing affected systems, eradicating malicious artifacts, recovering services securely, and performing post-incident analysis. This structured approach ensures thorough evidence gathering and system restoration.

Can I use this incident response skill for post-incident analysis and lessons learned?

Yes, you can use this incident response skill for post-incident analysis. It explicitly supports the final phase of the SANS framework, guiding cybersecurity teams through documenting lessons learned to improve future preparation and breach handling.

Do I need to install any dependencies to run structured incident response procedures?

No, you do not need to install any dependencies to run these incident response procedures. The skill operates independently to provide actionable plans and command lists for suspected server breaches without requiring external modules.