security-incident-response

Detect, contain, and recover from security incidents using structured IR phases.

207|31|Updated Mar 14, 2026
One-click install
npx skills add https://github.com/AbsolutelySkilled/AbsolutelySkilled --skill security-incident-response-absolutelyskilled
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: security-incident-response
Source: https://github.com/AbsolutelySkilled/AbsolutelySkilled/tree/main/skills/security-incident-response
Command: npx skills add https://github.com/AbsolutelySkilled/AbsolutelySkilled --skill security-incident-response-absolutelyskilled

SYSTEM DOCUMENTATION & REQUIREMENTS

💡 This Skill includes references (resource) components.

What problem does it solve?

This skill provides a production-grade framework to detect, contain, and recover from security incidents, enabling fast triage, evidence preservation, and clear stakeholder communications.

Core Features & Use Cases

  • Structured incident lifecycle aligned with NIST IR: preparation, detection, containment, eradication, recovery, and lessons learned.
  • Playbooks, templates, and guidelines for containment, evidence handling, communications, and incident reporting.
  • Lightweight integration with AI agents and tooling to support real-time triage, decision-making, and post-incident improvements.

Quick Start

Initiate the incident response workflow for a suspected breach and generate an action plan.

Frequently Asked Questions about security-incident-response

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I structure incident response for a security breach?

Structure incident response using a lifecycle aligned with NIST IR phases: preparation, detection, containment, eradication, recovery, and lessons learned. This framework provides playbooks and templates to guide triage and recovery actions.

What is the best way to preserve evidence and maintain chain of custody during incident triage?

The best way to maintain chain of custody during incident triage is to follow structured evidence preservation guidelines. This framework specifies IOC handling and chain of custody protocols to securely manage forensic data.

Can I use this incident response framework for real-time security triage?

Yes, you can use this incident response framework for real-time security triage. It supports lightweight integration with AI agents and tooling to facilitate fast decision-making and immediate action plan generation.

How do you classify security incident severity for enterprise containment?

Security incident severity is classified using defined severity classifications within the framework. This allows enterprises to prioritize containment strategies and coordinate stakeholder communications based on incident impact.

Does this incident response framework include templates for stakeholder communication?

Yes, the incident response framework includes templates and guidelines for stakeholder communication. These ensure clear, structured reporting and coordination throughout the incident lifecycle and post-mortem phases.

What should I include in a post-mortem report after security incident recovery?

A post-mortem report after security incident recovery should include lessons learned, structured incident reports, and evaluation checks. The framework provides structured templates to document these improvements and finalize the lifecycle.