security-incident-reporting

Generate security incident reports using NIST SP 800-61 and SANS-aligned templates.

33|6|Updated Jan 2, 2026
One-click install
npx skills add https://github.com/dirnbauer/webconsulting-skills --skill security-incident-reporting
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: security-incident-reporting
Source: https://github.com/dirnbauer/webconsulting-skills/tree/main/skills/security-incident-reporting
Command: npx skills add https://github.com/dirnbauer/webconsulting-skills --skill security-incident-reporting

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

This Skill provides a structured framework to document and analyze security incidents using NIST SP 800-61 and SANS-based templates, enabling consistent post-mortems, audits, and stakeholder communications.

Core Features & Use Cases

  • Incident reporting templates: metadata, timeline, IoCs, root-cause analysis, and remediation sections aligned with industry best practices.
  • CVE correlation & classification: map observed indicators to known CVEs for threat intelligence integration.
  • Post-incident playbooks: pre-built runbooks, checklists, and escalation paths to streamline containment and recovery.

Quick Start

Create a Security Incident Report for a detected event, including a metadata section, incident timeline, IoCs, and suggested remediation steps.

Frequently Asked Questions about security-incident-reporting

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I generate a security incident report aligned with NIST SP 800-61?

To generate a security incident report aligned with NIST SP 800-61, input your detected event data to populate structured sections for metadata, incident timeline, IoCs, and suggested remediation steps automatically.

What should be included in a post-mortem analysis for a security breach?

A post-mortem analysis for a security breach should include incident metadata, a detailed timeline, indicators of compromise, root-cause analysis, and remediation sections aligned with SANS and NIST best practices.

Can I map observed indicators of compromise to known CVEs during incident reporting?

Yes, you can map observed indicators of compromise to known CVEs during incident reporting to integrate threat intelligence and classify the security event accurately.

Does this approach work for documenting DDoS attacks and other network security events?

Yes, this approach works for documenting DDoS attacks and various security events by providing structured templates, post-incident playbooks, and escalation paths to streamline containment and recovery.

What is the best way to standardize post-incident playbooks and escalation paths?

The best way to standardize post-incident playbooks and escalation paths is using pre-built runbooks and checklists aligned with SANS templates to ensure consistent containment, recovery, and executive communications.

How do I structure executive communications for a security incident?

To structure executive communications for a security incident, use standardized reporting templates that summarize metadata, incident timelines, root-cause analysis, and remediation steps for stakeholder review.