post-incident-analysis
Installation
SKILL.md
Post-Incident Analysis
Overview
This skill provides a structured methodology for conducting post-incident reviews (PIRs) of closed security incidents in ServiceNow Security Operations. It reconstructs the incident timeline, identifies gaps in detection and response processes, and generates comprehensive lessons-learned documentation.
Key capabilities:
- Reconstruct a complete chronological timeline from incident creation through resolution
- Calculate key response metrics (time to detect, contain, eradicate, recover)
- Identify detection gaps where indicators were missed or delayed
- Analyze response effectiveness and process adherence
- Document root cause findings and contributing factors
- Generate actionable improvement recommendations
- Create structured lessons-learned records
When to use: After a security incident has been resolved and closed, typically within 5-10 business days of closure for major incidents or as part of periodic review cycles for lower-severity events.