incident-response-playbook

Generate NIST, ISO, and SANS aligned incident response playbooks for AI-class incidents.

Updated May 11, 2026
One-click install
npx skills add https://github.com/blamejs/exceptd-skills --skill incident-response-playbook
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: incident-response-playbook
Source: https://github.com/blamejs/exceptd-skills/tree/main/skills/incident-response-playbook
Command: npx skills add https://github.com/blamejs/exceptd-skills --skill incident-response-playbook

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

Legacy incident response playbooks are outdated for mid-2026 threat realities: they lack coverage for AI-class incidents (prompt injection breaches, model exfiltration, AI-API C2 channels, AI-agent unauthorized actions), do not operationalize compressed cross-jurisdiction regulator notification clocks (EU CRA 24h, NIS2 24h, CERT-In 6h, AU SOCI 12h, etc.), and fail to address ephemeral cloud evidence preservation gaps for serverless and containerized workloads. This skill fills those gaps with actionable, framework-aligned playbook content.

Core Features & Use Cases

  • Multi-framework alignment: Integrates NIST SP 800-61r3, ISO/IEC 27035-1/2:2023, and SANS PICERL phases, with explicit mapping to MITRE ATT&CK v19.1 and MITRE ATLAS v2026.06 TTPs.
  • AI-class incident coverage: Includes dedicated handling steps for prompt injection breaches, model exfiltration, AI-API C2 (SesameOp pattern), and AI-agent-initiated unauthorized actions, which are absent from legacy IR literature.
  • Global regulator clock matrix: Operationalizes notification timing requirements for 15+ global jurisdictions and sectoral regimes (EU CRA, NIS2, DORA, AI Act, NYDFS, CERT-In, AU SOCI, HIPAA, NERC CIP-008, etc.) to ensure parallel compliance during incidents.
  • Incident exemplar and TTP mapping: Provides TTP-to-PICERL phase response procedures for common incident TTPs (T1486, T1041, T1078, AML.T0096, AML.T0017, AML.T0051) and exploit availability matrices for 2024-2026 high-profile incident exemplars (Change Healthcare ransomware, Snowflake tenant compromise, MOVEit/Cl0p, Anthropic/OpenAI AI bug bounty disclosures, etc.).
  • Use case: A healthcare SOC team can use this playbook to handle a prompt injection breach of an internal AI diagnostic assistant, run parallel 24h EU CRA and NIS2 notification clocks, preserve ephemeral Lambda workload telemetry, and feed post-incident lessons learned to their zeroday gap tracking process.

Quick Start

Use the incident-response-playbook skill to build a compliant incident response workflow for a prompt injection breach of your enterprise AI assistant, covering regulator notification timing, ephemeral evidence preservation, and post-incident lessons learned.

Frequently Asked Questions about incident-response-playbook

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I build an incident response playbook for AI prompt injection breaches?

Build an incident response playbook for AI prompt injection breaches by mapping SANS PICERL phases to MITRE ATLAS TTPs, executing AI-class containment steps, and preserving ephemeral cloud telemetry across serverless workloads.

What are the global regulator notification clocks for incident response compliance?

Global incident response compliance clocks require rapid breach notifications across jurisdictions, such as 24 hours for EU CRA and NIS2, 12 hours for AU SOCI, and 6 hours for CERT-In, which must be operationalized in parallel during containment.

How do I map MITRE ATT&CK TTPs to NIST 800-61r3 incident response phases?

Map MITRE ATT&CK TTPs to NIST 800-61r3 incident response phases by aligning specific detection and response procedures for techniques like T1486 and T1041 directly to the corresponding preparation, detection, containment, and recovery stages.

How do you preserve ephemeral cloud evidence during a serverless incident response?

Preserve ephemeral cloud evidence during serverless incident response by capturing Lambda and container workload telemetry immediately during detection, ensuring volatile data is secured before workload termination for forensic analysis.

Can I use a single incident response framework for both traditional cyber and AI-class incidents?

Yes, you can handle both traditional and AI-class incidents within a single framework by integrating NIST SP 800-61r3, ISO 27035, and SANS PICERL, while mapping ATT&CK and ATLAS TTPs to unified response procedures.

What is the best way to handle cross-jurisdictional breach notifications during a ransomware incident?

Handle cross-jurisdictional breach notifications during ransomware incidents by running parallel compliance clocks for regimes like HIPAA and NYDFS, using a global regulator matrix to track mandatory reporting timelines concurrently.