ir-playbook

Generate structured incident response plans based on NIST and SANS frameworks.

Updated Apr 19, 2026
One-click install
npx skills add https://github.com/do360now/security-agents --skill ir-playbook
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: ir-playbook
Source: https://github.com/do360now/security-agents/tree/main/.claude/skills/ir-playbook
Command: npx skills add https://github.com/do360now/security-agents --skill ir-playbook

SYSTEM DOCUMENTATION & REQUIREMENTS

💡 This Skill includes references (resource) components.

What problem does it solve?

This Skill provides a comprehensive, structured approach to managing and responding to security incidents, streamlining the entire process from detection to post-incident analysis.

Core Features & Use Cases

  • Incident Management: Guides users through classifying, containing, and eradicating security incidents based on authoritative frameworks.
  • Documentation & Decision Making: Produces detailed incident reports, timelines, and escalation decisions to ensure accountability and clear communication.
  • Use Case: A security team detects a suspicious activity; they utilize this Skill to classify the incident, determine severity, and generate an exact incident report ready for stakeholder notification and regulatory compliance.

Quick Start

Initiate the incident response process by inputting the incident details and let the Skill generate a complete incident report outline.

Frequently Asked Questions about ir-playbook

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
What is a structured incident response workflow based on NIST and SANS frameworks?

A structured incident response workflow based on NIST and SANS frameworks systematically guides security analysts through incident classification, containment, eradication, and post-incident analysis to ensure compliance and effective coordination.

How do I classify a security incident and determine its severity for stakeholder escalation?

To classify a security incident and determine severity, you input the incident details into the workflow, which then generates classification decisions, containment strategies, and exact incident reports ready for stakeholder escalation.

Can I use this incident response plan to generate compliance reports for regulatory notification?

Yes, you can use this incident response plan to generate compliance reports. It produces detailed incident timelines and documentation that ensure accountability and are ready for stakeholder notification and regulatory compliance.

Does this incident response workflow support containment strategies and eradication procedures?

Yes, this incident response workflow supports containment strategies and eradication procedures. It provides step-by-step guidance on managing security events from initial detection through complete eradication and post-incident analysis.

What is the best way to document a security event for post-incident analysis and accountability?

The best way to document a security event for post-incident analysis is using a structured workflow that produces detailed incident reports and timelines, ensuring clear communication and accountability throughout the incident lifecycle.

Do I need prior forensics knowledge to use this incident response automation?

No prior forensics knowledge is strictly required to use this incident response automation. The Skill provides a step-by-step structured plan that guides security analysts through the entire process from detection to post-incident analysis.