incident-summarization

Generate executive and technical security incident reports with MITRE ATT&CK mappings.

34|13|Updated Feb 6, 2026
One-click install
npx skills add https://github.com/Happy-Technologies-LLC/happy-servicenow-skills --skill incident-summarization
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: incident-summarization
Source: https://github.com/Happy-Technologies-LLC/happy-servicenow-skills/tree/main/skills/secops/incident-summarization
Command: npx skills add https://github.com/Happy-Technologies-LLC/happy-servicenow-skills --skill incident-summarization

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

SOC teams require consistent, timely summaries of security incidents to inform leadership and coordinate response across teams.

Core Features & Use Cases

  • Generate executive summaries for leaders and technical summaries for responders, with MITRE ATT&CK mapping.
  • Aggregate incident details, observables, containment status, and affected assets into structured reports.
  • Use case: create post-incident briefs for management reviews and regulatory documentation.

Quick Start

Provide a concise executive and technical incident briefing based on the current incident data.

Frequently Asked Questions about incident-summarization

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I generate a security incident summary for leadership briefings?

Generate security incident summaries by processing incident records, affected CIs, IOCs, and containment status to produce structured executive and technical briefs with MITRE ATT&CK mappings for leadership briefings.

What is included in a post-incident report for SOC operations?

Post-incident reports for SOC operations aggregate incident details, observables, affected assets, containment status, and MITRE ATT&CK mappings into executive and technical summaries for management reviews and regulatory documentation.

Can I map security incidents to MITRE ATT&CK techniques automatically?

Yes, you can map security incidents to MITRE ATT&CK techniques by providing incident records and IOCs to generate structured executive and technical reports that include recommended actions with ATT&CK mappings.

Does incident summarization work with ServiceNow incident records?

Incident summarization works with ServiceNow by processing incident records, affected configuration items, and containment status to generate structured executive and technical reports with MITRE ATT&CK mappings for cross-team coordination.

What data is required to create an actionable incident brief?

Creating an actionable incident brief requires incident records, affected CIs, IOCs, containment status, and recommended actions with MITRE ATT&CK mappings to generate concise executive and technical summaries for responders and leadership.

Are there limitations when summarizing incidents without containment status data?

Summarizing incidents without containment status data limits the completeness of actionable briefs, as containment status is a required input to generate accurate executive and technical reports with recommended actions and MITRE ATT&CK mappings.