incident-response-playbook-generator

Generate incident response playbooks for AWS, GCP, and Azure security incidents.

1|Updated Feb 26, 2026
One-click install
npx skills add https://github.com/webrix-ai/agent-skills --skill incident-response-playbook-generator-webrix-ai
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: incident-response-playbook-generator
Source: https://github.com/webrix-ai/agent-skills/tree/main/skills/incident-response-playbook-generator
Command: npx skills add https://github.com/webrix-ai/agent-skills --skill incident-response-playbook-generator-webrix-ai

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

It helps security and engineering teams turn cloud incident knowledge into clear, repeatable playbooks that reduce confusion during a real event.

Core Features & Use Cases

  • Builds incident catalogs for compromised credentials, data exposure, cryptomining, unauthorized resource creation, ransomware, DDoS abuse, and insider threat scenarios.
  • Documents detection signals, containment actions, eradication steps, recovery checks, and post-incident review guidance for AWS, GCP, or Azure.
  • Produces structured runbooks and can organize the output for GitHub or Notion so teams have a shared incident response hub.

Quick Start

Ask this skill to create incident response playbooks for your cloud environment, specifying the platform, incidents to cover, team size, and where you want the runbooks delivered.

Frequently Asked Questions about incident-response-playbook-generator

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I create incident response playbooks for cloud security incidents?

Generate incident response playbooks by specifying your cloud platform (AWS, GCP, or Azure) and the incident types to cover, such as compromised credentials, data exposure, or cryptomining. The skill outputs structured runbooks containing detection, containment, eradication, recovery, and post-incident review steps.

What should an incident response runbook include for ransomware or unauthorized access?

An incident response runbook for ransomware or unauthorized access should include documented detection signals, containment actions, eradication steps, recovery validation checks, and post-incident review guidance tailored to your specific cloud environment.

Can I generate cloud incident playbooks and export them directly to Notion or GitHub?

Yes, you can generate cloud incident playbooks and organize the output directly into GitHub or Notion. This uses integrated MCP output to help your team build a shared, centralized incident response hub.

Does this incident response generator support AWS, GCP, and Azure environments?

Yes, the incident response generator supports AWS, GCP, and Azure environments. It builds incident catalogs and documents structured containment and recovery steps specifically for these cloud platforms.

What is the best way to document containment and eradication steps for a cryptomining attack?

The best way to document containment and eradication steps for a cryptomining attack is to generate a structured playbook that outlines specific detection signals, isolation actions, resource termination, and recovery validation checks for your cloud environment.

How do I build an incident catalog for insider threats and DDoS abuse in my cloud environment?

Build an incident catalog for insider threats and DDoS abuse by requesting playbooks for these specific scenarios. The skill structures the runbooks with the necessary detection rules, containment actions, and post-incident review templates for your cloud platform.