security-recommended-actions

Installation
SKILL.md

Security Incident Recommended Actions

Overview

This skill generates structured, prioritized response actions for security incidents by analyzing threat type, severity, affected assets, and organizational playbooks. It produces phased action plans covering containment, eradication, and recovery aligned with NIST SP 800-61 and organizational SOC procedures.

Key capabilities:

  • Threat-Specific Actions: Generate actions tailored to the specific threat category (malware, phishing, data exfiltration, DDoS, insider threat, etc.)
  • Severity-Based Prioritization: Scale response urgency and depth based on incident severity and business criticality
  • Asset-Aware Recommendations: Adjust actions based on the type, environment, and criticality of affected assets
  • Playbook Alignment: Map recommended actions to existing organizational playbooks and runbooks
  • Phased Response Plan: Structure actions into containment, eradication, recovery, and post-incident phases
  • MITRE ATT&CK Mapping: Reference specific ATT&CK techniques to guide detection and response
Installs
29
GitHub Stars
37
First Seen
Apr 29, 2026
security-recommended-actions — happy-technologies-llc/happy-platform-skills