responding-to-security-incidents

Generate incident response playbooks for containment, eradication, and recovery.

2.6k|379|Updated Oct 10, 2025
One-click install
npx skills add https://github.com/jeremylongshore/claude-code-plugins-plus --skill responding-to-security-incidents
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: responding-to-security-incidents
Source: https://github.com/jeremylongshore/claude-code-plugins-plus/tree/main/plugins/security/security-incident-responder/skills/security-incident-responder
Command: npx skills add https://github.com/jeremylongshore/claude-code-plugins-plus --skill responding-to-security-incidents

SYSTEM DOCUMENTATION & REQUIREMENTS

💡 This Skill includes scripts (resource) and references (resource) and assets (resource) components.

What problem does it solve?

This skill empowers Claude to guide you through the security incident response process, ensuring a structured and effective approach to handling security breaches and attacks. It helps you classify incidents, develop response strategies, gather crucial evidence, and implement remediation steps to minimize damage and prevent future occurrences.

Core Features & Use Cases

  • Incident Classification: Determine type, severity, and scope of security events.
  • Playbook Generation: Create tailored response playbooks for containment, eradication, and recovery.
  • Evidence Gathering: Guide collection of logs, network data, and forensic evidence.
  • Use Case: Respond to a ransomware attack by generating a playbook with steps for containment, eradication, and recovery from backups.

Quick Start

User request: "We've been hit with a ransomware attack. What should we do?"

The skill will:

  1. Classify the incident as a ransomware attack.
  2. Generate a response playbook including steps for containment (isolating affected systems), eradication (removing the ransomware), and recovery (restoring from backups).

Frequently Asked Questions about responding-to-security-incidents

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I respond to a security incident like ransomware or a data breach?

Security incident response involves classifying the breach type and severity, then executing a structured playbook for containment, eradication, and recovery. This skill guides you through incident classification, generates tailored response steps, and helps collect forensic evidence to minimize damage and prevent recurrence.

What steps should I take immediately after detecting a ransomware attack?

Immediate ransomware response prioritizes containment by isolating affected systems, then eradication by removing the malware, followed by recovery from backups. This skill generates a detailed playbook with specific containment, eradication, and recovery steps tailored to your incident.

How do I gather and preserve evidence during a security incident?

Evidence gathering during incident response requires collecting logs, network data, and forensic artifacts while maintaining chain of custody. This skill provides structured guidance on what evidence to collect, how to preserve it, and how to integrate collection with logging, forensic tools, and ticketing workflows.

Can I use incident response guidance for DDoS attacks and data breaches?

Yes, incident response applies across attack types including DDoS, ransomware, and data breaches. This skill classifies each incident type, generates appropriate response playbooks, and guides remediation steps specific to the attack's nature and scope.

What should I do after containing and remediating a security incident?

Post-incident analysis examines what happened, why it happened, and what prevents recurrence. This skill guides post-incident review, helps document lessons learned, and integrates findings with logging and ticketing systems to strengthen future defenses.