incident-response

Orchestrate security incident response using NIST SP 800-61 and SANS PICERL.

6|Updated May 30, 2026
One-click install
npx skills add https://github.com/jassics/awesome-claude-security --skill incident-response-jassics
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: incident-response
Source: https://github.com/jassics/awesome-claude-security/tree/main/plugins/dfir/skills/incident-response
Command: npx skills add https://github.com/jassics/awesome-claude-security --skill incident-response-jassics

SYSTEM DOCUMENTATION & REQUIREMENTS

💡 This Skill includes scripts (resource) and references (resource) components.

What problem does it solve?

This Skill guides users through the NIST SP 800-61 / SANS PICERL incident response lifecycle, ensuring a controlled response that limits damage and preserves evidence.

Core Features & Use Cases

  • Lifecycle Management: Triage and scope, contain, eradicate, recover, and capture lessons learned in a structured manner.
  • Incident Coordination: Helps coordinate or work an active incident with appropriate authority and roles.
  • Documentation: Generates an incident record with classification, scope, timeline, actions, IOCs, root cause, recovery status, and lessons.

Quick Start

Run the incident-response skill to initiate a new incident and begin the response process.

Frequently Asked Questions about incident-response

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I manage the security incident response lifecycle during an active event?

To manage the incident response lifecycle, this Skill orchestrates the process using NIST SP 800-61 and SANS PICERL frameworks, guiding you through triage, containment, eradication, and recovery to limit damage.

What is the best way to document a cybersecurity incident for lessons learned?

Documenting a cybersecurity incident involves generating a structured record with classification, scope, timeline, IOCs, root cause, recovery status, and lessons learned to preserve evidence and capture post-incident insights.

How do I coordinate roles and authority during a security incident?

To coordinate roles during a security incident, the Skill helps establish appropriate authority and role assignments, ensuring a controlled response across IT and cybersecurity teams throughout the active event.

Can I use this for incident triage and scoping before containment?

Yes, incident triage and scoping are handled as the initial lifecycle phase, allowing you to classify the event and define its boundaries before moving into containment, eradication, and recovery operations.

Do I need specific security operations tools to run the incident response process?

Yes, executing the incident response process requires proper incident handling procedures and security operations tools to actively manage containment, eradication, and recovery steps.

How does the SANS PICERL methodology apply to incident containment and recovery?

The SANS PICERL methodology applies to incident containment and recovery by providing a structured lifecycle that ensures actions are controlled, evidence is preserved, and systems are safely restored.