senior-secops

Triage security incidents and generate containment playbooks for on-prem and cloud environments.

5|Updated Jul 6, 2025
One-click install
npx skills add https://github.com/GuicedEE/ai-rules --skill senior-secops-guicedee
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: senior-secops
Source: https://github.com/GuicedEE/ai-rules/tree/main/skills/.curated/senior-secops
Command: npx skills add https://github.com/GuicedEE/ai-rules --skill senior-secops-guicedee

SYSTEM DOCUMENTATION & REQUIREMENTS

💡 This Skill includes scripts (resource) and references (resource) components.

What problem does it solve?

This Skill helps security teams rapidly triage alerts, contain incidents, and implement post-incident hardening with repeatable playbooks, reducing blast radius and downtime.

Core Features & Use Cases

  • Incident triage workflow: quickly assess impact, scope, and data at risk across on-prem and cloud environments.
  • Containment & eradication guidance: step-by-step actions to isolate affected systems, rotate credentials, and patch root causes.
  • Post-incident learning: generate postmortems and implement preventative controls to prevent recurrence.
  • Triage log analysis: leverage the included log_triage tool to summarize large log files for rapid pattern discovery.

Quick Start

Start by triaging the alert, determine impacted assets, then contain, eradicate, recover, and capture a postmortem.

Frequently Asked Questions about senior-secops

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I triage security alerts to determine impact and scope?

Security incident triage assesses impact, scope, and data at risk across on-prem and cloud environments. It generates actionable playbooks that guide containment, eradication, and recovery to minimize blast radius and downtime.

What's the best way to generate containment and eradication playbooks for incident response?

Incident response playbooks provide step-by-step actions to isolate affected systems, rotate credentials, and patch root causes. This structured workflow ensures repeatable containment and eradication across on-prem and cloud environments.

Can I use this for security log analysis and threat hunting?

Yes, security log analysis and threat hunting are supported through a log triage tool that summarizes large log files for rapid pattern discovery. This accelerates identifying threats during alert triage and incident investigation.

Does this incident triage workflow work across both on-prem and cloud environments?

Incident triage workflows apply across both on-prem and cloud environments. This ensures consistent assessment of impacted assets, containment actions, and post-incident hardening regardless of infrastructure deployment type.

How do I capture post-incident learning and implement preventative controls?

Post-incident learning generates postmortems and implements preventative controls to prevent recurrence. This structured approach ensures evidence capture and repeatable hardening steps after containment and recovery are complete.