respond-phishing

Guide phishing incident response through a PICERL workflow across mail gateways and SIEM.

120|34|Updated May 9, 2025
One-click install
npx skills add https://github.com/dandye/ai-runbooks --skill respond-phishing
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: respond-phishing
Source: https://github.com/dandye/ai-runbooks/tree/main/skills/respond-phishing
Command: npx skills add https://github.com/dandye/ai-runbooks --skill respond-phishing

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

This skill helps security teams rapidly respond to phishing incidents by guiding responders through a PICERL-based workflow to analyze artifacts, identify affected recipients, and remove malicious emails from mailboxes.

Core Features & Use Cases

  • PICERL-guided incident response for phishing scenarios.
  • Artifact analysis, IOC enrichment, containment, eradication, and recovery guidance.
  • Use Case: Respond to a reported phishing email across mail gateways and mailboxes, determine who clicked, and enact remediation steps.

Quick Start

Follow the PICERL workflow to respond to a phishing incident by providing CASE_ID and artifacts, then execute identification, containment, eradication, and recovery steps.

Frequently Asked Questions about respond-phishing

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I respond to a phishing incident using a PICERL framework?

Phishing incident response with PICERL guides security teams through structured phases to analyze artifacts and identify affected recipients. By applying this workflow across mail gateways and mailboxes, responders can determine who clicked malicious emails and enact coordinated remediation steps to remove threats.

How does IOC analysis work during phishing remediation?

IOC analysis during phishing remediation works by examining artifacts to enrich malicious indicators and determine affected users across mail gateways and SIEM contexts. Integrating with SOAR, GTI, and MCP tools automates evidence collection to identify clicked recipients and coordinate structured phase outputs for containment and eradication.

Can I use this phishing response workflow with my SIEM and SOAR tools?

Yes, you can use this phishing response workflow with your SIEM and SOAR tools. The framework integrates with SOAR, GTI, and MCP tools for automation and evidence collection, applying across mail gateways, mailboxes, and SIEM contexts to determine affected users and malicious indicators during remediation.

What is the best way to identify which users clicked a phishing email?

The best way to identify which users clicked a phishing email is to apply a PICERL-driven workflow across mail gateways and mailboxes. This approach analyzes artifacts and malicious indicators to determine affected recipients and clicked users, integrating with SIEM contexts for comprehensive visibility.

Do I need specific roles to ensure responsible use of this incident response framework?

Yes, specific roles are required to ensure responsible use of this incident response framework. The PICERL-driven workflow mandates required roles when identifying phishing incidents, analyzing artifacts, and coordinating remediation across mail gateways and mailboxes to maintain structured phase outputs.