incident_response

Classify security incidents and generate response playbooks with evidence gathering.

43|11|Updated Dec 27, 2025
One-click install
npx skills add https://github.com/vuralserhat86/antigravity-agentic-skills --skill incident-response-vuralserhat86
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: incident_response
Source: https://github.com/vuralserhat86/antigravity-agentic-skills/tree/main/skills/incident_response
Command: npx skills add https://github.com/vuralserhat86/antigravity-agentic-skills --skill incident-response-vuralserhat86

SYSTEM DOCUMENTATION & REQUIREMENTS

💡 This Skill includes references (resource) and scripts (resource) components.

What problem does it solve?

This skill provides a structured and effective approach to handling security breaches and attacks, ensuring minimal damage and preventing future occurrences.

Core Features & Use Cases

  • Incident Classification: Determines the type, severity, and scope of security events.
  • Playbook Generation: Creates tailored response plans for containment, eradication, and recovery.
  • Evidence Gathering: Guides the collection of logs, network data, and forensic evidence.
  • Remediation Planning: Develops plans to fix vulnerabilities and restore systems.
  • Use Case: When a ransomware attack is detected, this skill helps classify it, generate a containment and recovery playbook, and guides evidence collection.

Quick Start

Guide me through responding to a suspected ransomware attack on our production servers.

Frequently Asked Questions about incident_response

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I coordinate security incident response for a suspected ransomware attack?

Security incident response coordination involves classifying the attack, generating a tailored containment playbook, gathering forensic evidence, and planning recovery. This skill automates that workflow from identification through eradication and follow-up based on NIST and SANS best practices.

What's the best way to classify security incidents by severity and scope?

Classifying security incidents requires determining the event type, severity level, and affected scope. This skill automates incident classification to ensure appropriate response prioritization and generates tailored playbooks for containment, eradication, and recovery.

How does incident response playbook generation work for containment and recovery?

Incident response playbook generation creates tailored action plans for containment, eradication, and recovery phases. The skill validates these response strategies against best practices from NIST SP 800-61 Rev. 2 and the SANS Incident Handler's Handbook to ensure compliance.

Do I need NIST or SANS compliance frameworks to use this incident response workflow?

No external compliance framework installation is required. The skill internally validates response strategies against NIST SP 800-61 Rev. 2 and the SANS Incident Handler's Handbook, embedding those best practices directly into its automated preparation, identification, and remediation workflows.

Can I automate forensic evidence gathering for network data and logs during a breach?

Automating forensic evidence gathering guides the collection of logs, network data, and other forensic artifacts during a security incident. The skill supports automated workflows across preparation, identification, containment, eradication, recovery, and follow-up stages.

When should I use an automated incident response playbook instead of manual remediation planning?

Automated incident response playbooks are ideal when a structured approach is needed to minimize damage and prevent future occurrences. Use it when you need to validate strategies against NIST and SANS standards while coordinating classification, evidence gathering, and remediation systematically.