respond-ransomware

Coordinate ransomware response phases using the PICERL framework.

120|34|Updated May 9, 2025
One-click install
npx skills add https://github.com/dandye/ai-runbooks --skill respond-ransomware
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: respond-ransomware
Source: https://github.com/dandye/ai-runbooks/tree/main/skills/respond-ransomware
Command: npx skills add https://github.com/dandye/ai-runbooks --skill respond-ransomware

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

Ransomware incidents require a structured, end-to-end response that coordinates detection, containment, eradication, and recovery across multiple tools and teams. This skill provides a PICERL-based playbook to guide analysts through rapid containment and thorough remediation, minimizing downtime and data loss.

Core Features & Use Cases

  • Orchestrated lifecycle: identification, containment, eradication, and recovery following PICERL.
  • Interlocks with SIEM/SOAR/GTI data and supports case documentation for audit trails.
  • Use Case: When ransomware is detected, trigger containment actions, isolate affected hosts, and document eradication steps to restore operations.

Quick Start

Initiate the ransomware response workflow by supplying CASE_ID and INITIAL_INDICATORS to trigger identification, containment, eradication, and recovery steps.

Frequently Asked Questions about respond-ransomware

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I lead a structured ransomware incident response across endpoints and networks?

Trigger ransomware response workflows by supplying a CASE_ID and INITIAL_INDICATORS. The workflow then executes identification, containment, eradication, and recovery steps based on the PICERL framework to restore operations.

Can I use this PICERL workflow with my existing SIEM and EDR tools?

The workflow enforces case documentation and phase outputs to satisfy audit trail requirements. It interlocks with SIEM, SOAR, and GTI data to ensure all containment and eradication steps are thoroughly recorded for review.

How do I isolate affected hosts and document eradication steps during a ransomware attack?

The ransomware response workflow enforces case documentation and defined phase outputs. This satisfies audit trail requirements by recording all identification, containment, eradication, and recovery actions taken during the incident.

What is the best way to coordinate ransomware containment and recovery using SOAR workflows?

Use the ransomware response workflow when you need rapid containment and thorough remediation across multiple teams. It provides a structured, end-to-end response that coordinates detection and recovery actions during active incidents.