Dnr Respond

Incident response workup for a lead in hand — an alert, an IOC, or a /dnr-hunt finding. Scopes the lead across the logs, verdicts whether the attack succeeded, quantifies blast radius, confirms root cause in source with a local PoC, and writes a proposed (never executed) containment/remediation/recovery plan. Use when asked to "respond to this alert", "work this incident", "how bad is this", or "run dnr-respond". /dnr-hunt is the no-alert entry to the same track.

anthropics fa891c7 2 files · 15.7 KB Updated

File contents

anthropics/defending-code-reference-harness/tree/main/.claude/skills/dnr-respond commit fa891c737a

Frequently asked questions

npx skillmds@latest add anthropics/dnr-respond