What problem does it solve?
It helps you quickly classify a security incident, contain it safely, preserve evidence, and produce an actionable initial triage plan aligned to NIST SP 800-61.
Core Features & Use Cases
- Incident classification & severity: Identify malware, unauthorized access, exfiltration, DoS, web compromise, and phishing/social engineering, then assign severity (Critical/High/Medium/Low).
- Safe initial containment actions: Choose containment steps that prioritize human safety, limit spread, and preserve volatile evidence (including guidance not to power off systems when volatile memory is important).
- Evidence preservation & IOC extraction: Capture artifacts in order of volatility, document analysis findings, and extract indicators of compromise to support downstream analysis and reporting.
Use case example: When your SOC flags suspicious activity that could indicate credential compromise, use this skill to rapidly determine likely incident type and severity, isolate affected hosts, preserve relevant logs/process/network evidence, and output an incident triage report with IOCs for follow-on investigation.
Quick Start
Use the incident-triage skill when you need to triage a suspected security incident and produce an initial containment-and-evidence plan.