security-recommended-actions

Generate phased security incident response actions with MITRE mappings.

34|13|Updated Feb 6, 2026
One-click install
npx skills add https://github.com/Happy-Technologies-LLC/happy-servicenow-skills --skill security-recommended-actions
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: security-recommended-actions
Source: https://github.com/Happy-Technologies-LLC/happy-servicenow-skills/tree/main/skills/secops/security-recommended-actions
Command: npx skills add https://github.com/Happy-Technologies-LLC/happy-servicenow-skills --skill security-recommended-actions

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

This skill generates structured, prioritized containment, eradication, and recovery actions for security incidents, ensuring consistent, rapid responses.

Core Features & Use Cases

  • Threat-specific actions tailored to incident category and severity
  • Playbook-aligned guidance with MITRE ATT&CK mapping
  • Suitable for initial triage, escalation, and post-incident reviews

Quick Start

Ask your AI to generate a phased incident response plan for a detected security incident.

Frequently Asked Questions about security-recommended-actions

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I generate a structured incident response plan for a detected security incident?

To generate an incident response plan, input the threat type, severity, and affected assets. The skill produces phased, action-ready tasks for containment, eradication, and recovery with assigned owners and timelines.

What are the key phases of security incident containment and recovery?

Security incident containment and recovery involve phased actions: initial triage, containment to limit spread, eradication of the threat, recovery of systems, and post-incident review. The skill structures these steps with playbook alignment.

Can I map incident response actions to MITRE ATT&CK techniques during triage?

Yes, you can map incident response actions to MITRE ATT&CK techniques. The skill generates threat-specific guidance that aligns containment and eradication steps with relevant MITRE ATT&CK mappings for escalations.

How do I assign role-based ownership and timelines for incident response tasks?

You can assign role-based ownership and timelines by generating actionable tasks through the skill. It produces structured incident records that specify owners, timelines, and documentation requirements for evidence preservation.

Does this approach support post-incident reviews and escalations?

Yes, this approach supports post-incident reviews and escalations. The skill applies its phased action generation to new incidents, escalations, and post-incident reviews, ensuring consistent documentation and recovery steps.

What is the best way to document evidence preservation during security incident response?

The best way to document evidence preservation is to use structured, phased response actions. The skill satisfies evidence preservation requirements by generating actionable tasks and documentation that can be loaded into incident records.