incident-response-playbook-creator

Generate NIST SP 800-61r3-based incident response playbooks in Markdown.

6|Updated Oct 18, 2025
One-click install
npx skills add https://github.com/diegocconsolini/ClaudeSkillCollection --skill incident-response-playbook-creator
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: incident-response-playbook-creator
Source: https://github.com/diegocconsolini/ClaudeSkillCollection/tree/main/incident-response-playbook-creator
Command: npx skills add https://github.com/diegocconsolini/ClaudeSkillCollection --skill incident-response-playbook-creator

SYSTEM DOCUMENTATION & REQUIREMENTS

💡 This Skill requires jinja2, markdown, pyyaml, and includes scripts (resource) and references (resource) and templates (resource) and assets (resource) components.

What problem does it solve?

Produces customized incident response playbooks for 11 scenarios using NIST SP 800-61r3, CISA guidance, and related NIST publications, including GDPR/HIPAA considerations.

Core Features & Use Cases

  • 11 comprehensive IR playbooks (ransomware, data breach, phishing, AI/ML incidents, etc.)
  • GDPR/HIPAA breach-notification guidance and CSF 2.0 alignment
  • Outputs in Markdown with templates, plus optional PDF/HTML via additional tooling

Quick Start

"Create an incident response playbook for ransomware" — Claude will guide you through the interactive prompts and generate a Markdown playbook.

Frequently Asked Questions about incident-response-playbook-creator

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I create incident response playbooks for different security scenarios?

Incident response playbooks are step-by-step guides for detecting, responding to, and recovering from security incidents. This Skill generates customized Markdown playbooks for 11 scenarios—ransomware, data breach, phishing, AI/ML incidents, supply chain, container, IoT/OT, cloud, API, insider threat, and DDoS—based on NIST SP 800-61r3 and CISA guidance, tailored to your industry, organization size, and regulatory requirements.

Does this cover GDPR and HIPAA breach notification requirements?

Yes. The playbooks include GDPR and HIPAA breach-notification guidance, detection indicators, response and recovery procedures, communication templates, escalation paths, and role definitions aligned with CSF 2.0 to meet regulatory compliance obligations across incident scenarios.

What format do the generated playbooks use?

Playbooks are generated as Markdown files containing structured detection indicators, response procedures, recovery steps, communication templates, escalation paths, and role definitions. Optional PDF or HTML output is available through additional tooling.

Can I customize playbooks for my organization's size and industry?

Yes. The Skill generates playbooks customized by organization size, industry type, and regulatory requirements. You provide these inputs during the interactive prompts, and the tool applies them across all 11 incident scenarios to produce relevant, context-specific guidance.

What dependencies does this Skill require?

The Skill uses Jinja2 for templating, Markdown for output formatting, and PyYAML for configuration parsing. These tools enable dynamic playbook generation from trusted templates and regulatory frameworks.

Does this align with NIST Cybersecurity Framework 2.0?

Yes. All generated playbooks include CSF 2.0 alignment, mapping incident response procedures to framework functions so your response actions support your broader cybersecurity governance and compliance posture.