incident-response

Classify security events, score severity, filter false positives, and guide forensic evidence collection.

Updated Aug 23, 2026
One-click install
npx skills add https://github.com/ThalesAndrades/forumfoup2026 --skill incident-response-thalesandrades
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: incident-response
Source: https://github.com/ThalesAndrades/forumfoup2026/tree/main/.claude/skills/incident-response
Command: npx skills add https://github.com/ThalesAndrades/forumfoup2026 --skill incident-response-thalesandrades

SYSTEM DOCUMENTATION & REQUIREMENTS

💡 This Skill requires jsonschema, datetime, and includes scripts (resource) and references (resource) components.

What problem does it solve?

It enables security teams to classify, triage, and manage security incidents efficiently, reducing response times and improving forensic readiness.

Core Features & Use Cases

  • Incident Classification: Automatically identify incident types based on event data and context.
  • False Positive Filtering: Detect benign alerts to prevent unnecessary escalations.
  • Severity Assessment & Escalation: Assign appropriate severity levels and route incidents to the right responders, such as SOC leads or legal teams.
  • Forensic Evidence Collection: Guide the collection and preservation of volatile and non-volatile evidence following best practices.
  • Use Case: When a suspected ransomware attack occurs, classify the alert, assess severity, filter false positives, and initiate forensic procedures all in one integrated process.

Quick Start

Input a security event in JSON format and run the incident response script to classify and triage it immediately.

Frequently Asked Questions about incident-response

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I classify and triage security incidents automatically?

To classify and triage security incidents automatically, you input security event data in JSON format to trigger analysis. The system then identifies incident types, scores severity, and filters false positives to facilitate rapid incident management.

What is the best way to filter false positives during security incident response?

Filtering false positives during security incident response involves analyzing event context to detect benign alerts. This automated detection prevents unnecessary escalations, ensuring responders focus on genuine threats and reducing overall response times.

Does this incident response process support forensic evidence collection?

Yes, the incident response process supports forensic evidence collection by guiding responders through preserving volatile and non-volatile evidence. It follows best practices to maintain forensic readiness during incident management.

How do I assess severity and route security incidents to the right responders?

Assessing severity and routing security incidents requires assigning appropriate severity levels based on event data. The system then escalates and routes incidents to the correct responders, such as SOC leads or legal teams.

Can I use JSON event data to trigger ransomware incident classification?

Yes, you can input a suspected ransomware attack event in JSON format to immediately classify the alert. The integrated process assesses severity, filters false positives, and initiates forensic procedures.

When should I use an automated tool for security event triage?

You should use an automated tool for security event triage when you need to reduce response times and improve forensic readiness across multiple alerts. It enables security teams to manage incidents efficiently.