post-incident-review

Guide security teams through post-incident analysis and documentation.

Updated Apr 19, 2026
One-click install
npx skills add https://github.com/do360now/security-agents --skill post-incident-review
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: post-incident-review
Source: https://github.com/do360now/security-agents/tree/main/.claude/skills/post-incident-review
Command: npx skills add https://github.com/do360now/security-agents --skill post-incident-review

SYSTEM DOCUMENTATION & REQUIREMENTS

💡 This Skill includes scripts (resource) and references (resource) components.

What problem does it solve?

This Skill provides structured guidance and analysis tools for conducting thorough post-incident reviews, helping security teams learn and improve after security events.

Core Features & Use Cases

  • Structured Post-Incident Analysis: Guides teams through blameless retrospective techniques, timeline reconstruction, root cause analysis, and control failure mapping.
  • Reporting and Remediation Tracking: Automatically generates comprehensive PIR reports with prioritized action plans and follow-up schedules.
  • Use Case: Following a significant security breach, security analysts can utilize this Skill to document the incident, analyze contributing factors, and plan systemic improvements efficiently.

Quick Start

Provide incident details and run the PIR to generate a detailed post-incident review report for organizational learning.

Frequently Asked Questions about post-incident-review

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I conduct a blameless post-incident review after a security breach?

Conduct a post-incident review by guiding your security team through blameless retrospective techniques, timeline reconstruction, root cause analysis, and control failure mapping to document the event and plan systemic improvements.

What is root cause analysis in cybersecurity incident response?

Root cause analysis in incident response determines the fundamental factors contributing to a security event by mapping control failures, enabling continuous security improvement and compliance audit readiness.

How do I generate a post-mortem report with prioritized remediation tracking?

Generate a post-mortem report by inputting structured incident data into an analysis methodology, which automatically produces comprehensive documentation with prioritized action plans and follow-up schedules.

Can I use structured incident data for compliance audits and continuous security improvement?

Yes, structured incident data facilitates comprehensive post-incident analysis applicable to compliance audits and continuous security improvement by mapping control failures and generating detailed reporting templates.

What is the best way to map control failures during a security incident analysis?

The best way to map control failures during security incident analysis is utilizing structured incident data and analysis methodologies to reconstruct the timeline and determine contributing factors.

Do I need structured incident data and reporting templates to perform a post-incident review?

Yes, performing a post-incident review requires structured incident data, analysis methodologies, and reporting templates to accurately reconstruct timelines, determine root causes, and generate comprehensive PIR reports.