What problem does it solve?
Legacy incident response playbooks are outdated for mid-2026 threat realities: they lack coverage for AI-class incidents (prompt injection breaches, model exfiltration, AI-API C2 channels, AI-agent unauthorized actions), do not operationalize compressed cross-jurisdiction regulator notification clocks (EU CRA 24h, NIS2 24h, CERT-In 6h, AU SOCI 12h, etc.), and fail to address ephemeral cloud evidence preservation gaps for serverless and containerized workloads. This skill fills those gaps with actionable, framework-aligned playbook content.
Core Features & Use Cases
- Multi-framework alignment: Integrates NIST SP 800-61r3, ISO/IEC 27035-1/2:2023, and SANS PICERL phases, with explicit mapping to MITRE ATT&CK v19.1 and MITRE ATLAS v2026.06 TTPs.
- AI-class incident coverage: Includes dedicated handling steps for prompt injection breaches, model exfiltration, AI-API C2 (SesameOp pattern), and AI-agent-initiated unauthorized actions, which are absent from legacy IR literature.
- Global regulator clock matrix: Operationalizes notification timing requirements for 15+ global jurisdictions and sectoral regimes (EU CRA, NIS2, DORA, AI Act, NYDFS, CERT-In, AU SOCI, HIPAA, NERC CIP-008, etc.) to ensure parallel compliance during incidents.
- Incident exemplar and TTP mapping: Provides TTP-to-PICERL phase response procedures for common incident TTPs (T1486, T1041, T1078, AML.T0096, AML.T0017, AML.T0051) and exploit availability matrices for 2024-2026 high-profile incident exemplars (Change Healthcare ransomware, Snowflake tenant compromise, MOVEit/Cl0p, Anthropic/OpenAI AI bug bounty disclosures, etc.).
- Use case: A healthcare SOC team can use this playbook to handle a prompt injection breach of an internal AI diagnostic assistant, run parallel 24h EU CRA and NIS2 notification clocks, preserve ephemeral Lambda workload telemetry, and feed post-incident lessons learned to their zeroday gap tracking process.
Quick Start
Use the incident-response-playbook skill to build a compliant incident response workflow for a prompt injection breach of your enterprise AI assistant, covering regulator notification timing, ephemeral evidence preservation, and post-incident lessons learned.