respond-compromised-account

Coordinate PICERL-based incident response to detect, contain, eradicate, and recover compromised accounts.

120|34|Updated May 9, 2025
One-click install
npx skills add https://github.com/dandye/ai-runbooks --skill respond-compromised-account
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: respond-compromised-account
Source: https://github.com/dandye/ai-runbooks/tree/main/skills/respond-compromised-account
Command: npx skills add https://github.com/dandye/ai-runbooks --skill respond-compromised-account

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

Respond to a potentially compromised user account by investigating activity, containing access, removing persistence, and restoring secure access using a PICERL-based workflow.

Core Features & Use Cases

  • Identify compromised accounts through SIEM, identity, and behavioral data
  • Contain, revoke sessions and credentials, and restore access with auditable steps
  • Eradicate persistence, verify clean endpoints, and monitor for recurrence

Quick Start

Invoke the respond-compromised-account skill with USER_ID and CASE_ID to begin the PICERL-driven containment and recovery workflow.

Frequently Asked Questions about respond-compromised-account

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I automate incident response for a compromised account?

Contain compromised accounts by integrating SIEM and behavioral data to identify threats, then revoking active sessions and credentials to restore secure access with auditable steps.

Can I use SOAR integrations to contain impossible travel incidents?

Yes, this Skill uses SOAR integrations to coordinate containment for impossible travel incidents, requiring analyst confirmation before executing any containment actions against the compromised account.

What is the PICERL workflow for credential stuffing recovery?

Eradicate persistence during account recovery by verifying clean endpoints, removing malicious access, and monitoring for recurrence to prevent further unauthorized activity.

Does this incident response workflow require analyst confirmation for containment?

Yes, this incident response workflow explicitly requires analyst confirmation before executing containment actions, ensuring human oversight when revoking sessions and credentials during a compromised account investigation.

How do I eradicate persistence after a phishing compromise?

Eradicate persistence after a phishing compromise by following the Skill's workflow to verify clean endpoints, remove malicious access tokens, and monitor for recurrence using integrated GTI and identity tooling.