running-cloud-ir-runbook

Coordinate cloud incident response across AWS, GCP, and Azure.

2|Updated May 23, 2026
One-click install
npx skills add https://github.com/rocklambros/rcs --skill running-cloud-ir-runbook
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: running-cloud-ir-runbook
Source: https://github.com/rocklambros/rcs/tree/main/skills/security/running-cloud-ir-runbook
Command: npx skills add https://github.com/rocklambros/rcs --skill running-cloud-ir-runbook

SYSTEM DOCUMENTATION & REQUIREMENTS

💡 This Skill includes references (resource) components.

What problem does it solve?

This Skill helps responders handle active or recent cloud security incidents without improvising the sequence of triage, evidence capture, containment, and recovery.

Core Features & Use Cases

  • Cloud triage and evidence preservation for AWS, GCP, and Azure alerts such as GuardDuty, Security Command Center, and Defender for Cloud.
  • Containment and blast-radius analysis for leaked credentials, suspicious cross-account access, public storage exposure, and compromised service identities.
  • Comms and recovery guidance for internal updates, customer or regulator notifications when regulated data is involved, and lessons-learned documentation with owners and deadlines.

Quick Start

Ask the skill to walk a specific cloud incident from alert to recovery, and include the provider, triggering signal, affected identity, account or subscription, alert window, and whether regulated data may be involved.

Frequently Asked Questions about running-cloud-ir-runbook

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I handle cloud incident response for GuardDuty alerts across AWS, GCP, and Azure?

Cloud incident response for GuardDuty alerts requires coordinated triage, evidence preservation, and containment. You must capture evidence before containment, analyze the blast radius, eradicate follow-on access paths, and document recovery controls with assigned owners.

What is the correct sequence for containing leaked credentials in a cloud environment?

Containing leaked credentials starts with preserving evidence before disabling the compromised identity. Next, execute provider-specific containment commands, analyze the blast radius for cross-account access, eradicate follow-on paths, and apply recovery controls to secure the environment.

Does cloud incident response require evidence preservation before containment for public storage exposure?

Yes, evidence preservation before containment is required for public storage exposure. Capturing logs and forensic snapshots first ensures the blast radius can be analyzed accurately, enabling proper eradication of follow-on access paths and recovery.

How do I document lessons learned after a cloud security incident involving regulated data?

Documenting lessons learned after a cloud security incident involves generating factual communications for regulators and internal teams. The output must include recovery controls, follow-on access path eradication steps, and assigned owners with deadlines for remediation tasks.

Can I use a single runbook for suspicious cross-account access across AWS, GCP, and Azure?

Yes, a single runbook can coordinate suspicious cross-account access response across AWS, GCP, and Azure. It applies provider-specific containment commands and blast-radius analysis to ensure consistent triage, evidence preservation, and recovery.

What should I include when triaging compromised service identities in Defender for Cloud?

Triage compromised service identities in Defender for Cloud by capturing evidence, executing containment commands, and analyzing the blast radius. You must also eradicate follow-on access paths and document lessons learned with owners and deadlines.