post-incident-review

Generate NIST SP 800-61 Rev 2 post-incident review reports with root cause analysis and metrics.

44|128|Updated Mar 6, 2026
One-click install
npx skills add https://github.com/UnitOneAI/SecuritySkills --skill post-incident-review-unitoneai
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: post-incident-review
Source: https://github.com/UnitOneAI/SecuritySkills/tree/main/skills/incident-response/post-incident-review
Command: npx skills add https://github.com/UnitOneAI/SecuritySkills --skill post-incident-review-unitoneai

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

It helps security teams produce a structured, blameless post-incident review that converts incident facts into measurable lessons learned, root cause findings, and trackable remediation actions.

Core Features & Use Cases

  • Blameless retrospective (NIST-aligned): Guides a no-fault review focused on systems and processes rather than assigning blame.
  • Timeline reconstruction + RCA: Rebuilds the incident sequence and applies structured root cause analysis (e.g., 5 Whys and/or fishbone).
  • Metrics and control failure mapping: Calculates MTTD, MTTC, and MTTR, then maps findings to preventive/detective/corrective control gaps with improvements.
  • Remediation plan with follow-up: Produces prioritized action items and a schedule for remediation review and PIR distribution.

Quick Start

Run the skill on your incident closeout artifacts by providing the resolved incident report or incident directory as the target argument: post-incident-review "[target-file-or-directory]".

Frequently Asked Questions about post-incident-review

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I conduct a blameless post-incident review for a resolved security incident?

A blameless post-incident review guides a no-fault retrospective focused on systems and processes. It reconstructs the incident timeline, applies structured root cause analysis, and calculates metrics like MTTD, MTTC, and MTTR to generate trackable remediation actions.

What is the best way to calculate MTTD, MTTC, and MTTR during incident closeout?

Calculating MTTD, MTTC, and MTTR during incident closeout involves mapping the incident timeline to detection, containment, and recovery phases. These metrics are then mapped against preventive, detective, and corrective control gaps to identify measurable improvements.

How do I map control failures to remediation actions after a security incident?

Mapping control failures to remediation actions requires analyzing the incident sequence to identify preventive, detective, and corrective control gaps. The review process translates these gaps into prioritized action items and schedules follow-up remediation reviews.

Can I use NIST SP 800-61 Rev 2 to structure my incident response post-incident activity?

NIST SP 800-61 Rev 2 provides the framework for structuring post-incident activity. It supports blameless retrospectives by enforcing timeline reconstruction, root cause analysis, and control failure mapping while preventing the exfiltration of sensitive incident data.

What is included in a post-incident report schema for root cause analysis?

A post-incident report schema for root cause analysis includes the reconstructed incident timeline, structured root cause findings using techniques like 5 Whys, calculated MTTD and MTTR metrics, and a prioritized remediation plan with follow-up schedules.