post-incident-analysis

Installation
SKILL.md

Post-Incident Analysis

Overview

This skill provides a structured methodology for conducting post-incident reviews (PIRs) of closed security incidents in ServiceNow Security Operations. It reconstructs the incident timeline, identifies gaps in detection and response processes, and generates comprehensive lessons-learned documentation.

Key capabilities:

  • Reconstruct a complete chronological timeline from incident creation through resolution
  • Calculate key response metrics (time to detect, contain, eradicate, recover)
  • Identify detection gaps where indicators were missed or delayed
  • Analyze response effectiveness and process adherence
  • Document root cause findings and contributing factors
  • Generate actionable improvement recommendations
  • Create structured lessons-learned records

When to use: After a security incident has been resolved and closed, typically within 5-10 business days of closure for major incidents or as part of periodic review cycles for lower-severity events.

Prerequisites

Installs
29
GitHub Stars
37
First Seen
Apr 29, 2026
post-incident-analysis — happy-technologies-llc/happy-platform-skills