linux-emergency-response

Automate Linux incident response checks over SSH with structured analysis.

4|1|Updated Jan 21, 2026
One-click install
npx skills add https://github.com/b0bac/AIEmergencyTools --skill linux-emergency-response
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: linux-emergency-response
Source: https://github.com/b0bac/AIEmergencyTools/tree/main/linux-emergency-response
Command: npx skills add https://github.com/b0bac/AIEmergencyTools --skill linux-emergency-response

SYSTEM DOCUMENTATION & REQUIREMENTS

💡 This Skill requires log-analysis-expert, network-forensics-tool, and includes scripts (resource) components.

What problem does it solve?

Linux 应急响应工作流往往需要在远程主机上进行繁琐、重复的检查与分析。本 Skill 自动化引导通过 SSH 连接在目标 Linux 系统上执行全面的入侵排查与威胁情报查询,显著缩短应急响应时间并提升分析一致性。

Core Features & Use Cases

  • 自动化 SSH 指导执行:通过内置工具集对用户/登录、进程、网络、日志等维度进行系统化排查与分析。
  • 威胁情报整合:集成 VirusTotal 与 WHOIS 查询,帮助安全分析师快速确认潜在威胁来源与域名注册信息。
  • 跨场景应用:适用于远程主机应急响应、事后取证、以及日常安全运维中的快速健康检查与合规性核验。

Quick Start

Connect to the target Linux host via SSH and start the automated incident response walkthrough.

Frequently Asked Questions about linux-emergency-response

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I automate Linux incident response over SSH?

To automate Linux incident response over SSH, you need a tool that orchestrates remote checks for user logins, processes, networks, and logs. This Skill automates that workflow by executing structured analysis and threat-intelligence lookups directly on the target host.

What is included in a remote Linux security investigation via SSH?

A remote Linux security investigation via SSH includes user and login audits, process and network investigations, log analysis, and threat-intelligence lookups. It validates SSH connection details, loads built-in analysis tools, and outputs formatted findings with guided remediation recommendations.

Can I query VirusTotal and WHOIS during Linux incident response?

Yes, you can query VirusTotal and WHOIS during Linux incident response. This Skill integrates threat-intelligence lookups to help security analysts quickly confirm potential threat sources and domain registration information while conducting remote host investigations.

Does Linux incident response work for post-incident forensics and compliance checks?

Linux incident response works for post-incident forensics and compliance checks. The automated SSH workflow applies to remote hosts in security incidents, performing structured analysis suitable for事后取证 and daily security operations like quick health checks and compliance verification.

Do I need built-in analysis tools to perform remote Linux intrusion checks?

You need built-in analysis tools to perform remote Linux intrusion checks effectively. This Skill loads internal analysis tools to systematize checks across users, processes, networks, and logs, applying input validation for SSH connection details before executing the automated response.