Contain Security Incident
Overview
Interrupt the validated path of harm with the smallest effective action, then verify the containment. Do not confuse a blocked symptom with eradication or recovery.
Read references/containment-plan.md before making disruptive changes.
Workflow
- Confirm incident lead, authority, current scope, harm path, critical services, evidence priorities, and emergency contacts.
- Model containment choices.
- Consider host/network isolation, process/service suspension, account disablement, session/token/key revocation, access-policy change, application feature disablement, route/rule changes, or provider controls.
- Record expected harm reduction, operational impact, volatile evidence loss, dependencies, rollback, and attacker visibility.
- Sequence actions.
- Address active exfiltration/destruction/safety first, then privileged access, propagation, persistence, and re-entry paths.
- Coordinate simultaneous identity, host, application, and network actions when staggered changes would alert or strand access.
- Apply approved changes.
- Record exact target, operator, time, command/control surface, result, failures, and unexpected effects.
- Verify containment.
- Check that the harmful path stopped, access/session state changed, affected services remain understood, and monitoring still functions.
- Expand scope carefully.
- Hunt for related indicators and access paths; update the incident record before new targets or actions.
- Define exit criteria.
- State what evidence permits eradication/recovery and what temporary controls must remain.
Output
Return containment objective, options/tradeoffs, actions/results, verification, residual access, business impact, temporary controls, rollback, and next-phase criteria.
1---2name: contain-security-incident3description: Contain an active or credible incident across hosts, identities, applications, cloud resources, networks, or data. Use when access, execution, exfiltration, fraud, destruction, or repeated compromise needs authorized interruption.4---56# Contain Security Incident78## Overview910Interrupt the validated path of harm with the smallest effective action, then verify the containment. Do not confuse a blocked symptom with eradication or recovery.1112Read [references/containment-plan.md](references/containment-plan.md) before making disruptive changes.1314## Workflow15161. Confirm incident lead, authority, current scope, harm path, critical services, evidence priorities, and emergency contacts.172. Model containment choices.18 - Consider host/network isolation, process/service suspension, account disablement, session/token/key revocation, access-policy change, application feature disablement, route/rule changes, or provider controls.19 - Record expected harm reduction, operational impact, volatile evidence loss, dependencies, rollback, and attacker visibility.203. Sequence actions.21 - Address active exfiltration/destruction/safety first, then privileged access, propagation, persistence, and re-entry paths.22 - Coordinate simultaneous identity, host, application, and network actions when staggered changes would alert or strand access.234. Apply approved changes.24 - Record exact target, operator, time, command/control surface, result, failures, and unexpected effects.255. Verify containment.26 - Check that the harmful path stopped, access/session state changed, affected services remain understood, and monitoring still functions.276. Expand scope carefully.28 - Hunt for related indicators and access paths; update the incident record before new targets or actions.297. Define exit criteria.30 - State what evidence permits eradication/recovery and what temporary controls must remain.3132## Output3334Return containment objective, options/tradeoffs, actions/results, verification, residual access, business impact, temporary controls, rollback, and next-phase criteria.