ise-incident-response

Installation
SKILL.md

ISE Incident Response

Safety -- Non-Negotiable Rules

NEVER auto-quarantine an endpoint. Endpoint group changes require explicit human confirmation. The agent MUST present its findings, state its recommendation, and then STOP and WAIT for the human to type an affirmative response before proceeding with any ISE endpoint group modification.

NEVER skip the investigation steps. Even if the human says "just quarantine MAC XX:XX:XX:XX:XX:XX", the agent MUST first collect endpoint data, auth history, and posture state so the quarantine action has full context for the ServiceNow ticket and GAIT audit trail.

NEVER modify ISE authorization policies during incident response. This workflow changes endpoint group membership only. Policy changes require a separate Change Request via servicenow-change-workflow.

When to Use

  • Suspected compromised endpoint (SOC alert, SIEM correlation)
  • Unauthorized device detected on the network
  • Endpoint exhibiting anomalous behavior (port scanning, lateral movement)
  • Failed posture compliance requiring immediate isolation
  • Rogue access point or hub detected on a switchport

How to Call the ISE MCP Tools

Related skills

More from automateyournetwork/netclaw

Installs
3
GitHub Stars
489
First Seen
Mar 6, 2026