responding-to-incidents

Installation
SKILL.md

Responding to Incidents

Two questions drive every incident: how far did they get, and are they still here. Everything else — the malware, the CVE, the root cause — is supporting detail. Answer those two in order and the response follows.

When to Use

  • Suspected or confirmed compromise of a host, account, or cloud tenant
  • Forensic analysis of a disk image, memory capture, or log set
  • Reconstructing what an attacker did and when
  • Scoping blast radius and deciding containment
  • Writing a postmortem or a regulator/customer-facing incident narrative

When NOT to Use

Installs
23
GitHub Stars
144
First Seen
Jul 31, 2026
responding-to-incidents — trilwu/secskills