What problem does it solve?
This Skill provides a structured playbook to detect, triage, contain, and remediate security incidents in production environments while preserving forensic evidence and producing an auditable incident report.
Core Features & Use Cases
- Immediate Response Checklist: Prioritized actions for the first 15 minutes including severity assessment, isolation, evidence preservation, and stakeholder notification.
- Forensic Investigation Guidance: Detailed steps for authentication and application log analysis, SQL and API audit queries, and identification of compromised accounts or malicious IPs.
- Containment & Remediation Procedures: Specific containment actions such as blocking IPs, revoking sessions, rotating credentials, and producing a remediation timeline and incident report for compliance reviews.
- Monitoring and Hardening: Templates and examples for audit logging middleware, automated alerts for suspicious activity, and recommended hardening measures like MFA and rate limiting.
Quick Start
Run the security-incident-specialist playbook to triage a suspected breach by preserving logs, isolating affected systems, revoking compromised credentials, and documenting all actions for an incident report.