building-incident-response-playbook

mukul975/building-incident-response-playbook · Agent Skill (multi-file)

by mukul975 · bundle

Published · Last updated


Designs and documents structured incident response playbooks aligned with NIST SP 800-61r3 and SANS PICERL frameworks, covering playbook structure, decision trees, escalation criteria, RACI matrices, and SOAR integration.

SKILL.md

Files

This skill is a package of 4 files. Install with the command above, or download the folder.

  • 📄SKILL.md entry
  • 📁references
  • 📄api-reference.md 2.3 KB
  • 📁scripts
  • ⚙️agent.py 9.5 KB
  • 📄LICENSE 11.0 KB

Related

  1. implementing-ot-incident-response-playbook · mukul975 bundle
    Develop and implement OT-specific incident response playbooks aligned with SANS PICERL framework, IEC 62443, and NIST SP 800-82 that address unique ICS challenges including safety-critical systems, limited downtime tolerance, and coordination between IT SOC, OT engineering, and plant operations teams.
    24.6k
    repo stars
  2. implementing-soar-playbook-with-palo-alto-xsoar · mukul975 bundle
    Automate incident response workflows in Cortex XSOAR by building playbooks that orchestrate security tools, enrich indicators, and execute containment actions.
    24.6k
    repo stars
  3. building-ransomware-playbook-with-cisa-framework · mukul975 bundle
    Builds a structured ransomware incident response playbook aligned with the CISA StopRansomware Guide and NIST Cybersecurity Framework, covering preparation, detection, containment, eradication, recovery, and post-incident phases with actionable checklists.
    24.6k
    repo stars
  4. implementing-soar-playbook-for-phishing · mukul975 bundle
    Automate phishing incident response by creating Splunk SOAR containers, adding artifacts, and triggering investigation playbooks.
    24.6k
    repo stars
  5. implementing-soar-automation-with-phantom · mukul975 bundle
    Automates alert triage, IOC enrichment, containment actions, and incident response playbooks using Splunk SOAR (Phantom) to reduce manual analyst work and standardize response procedures.
    24.6k
    repo stars
  6. conducting-post-incident-lessons-learned · mukul975 bundle
    Facilitate structured post-incident reviews to identify root causes, document what worked and failed, and produce actionable recommendations to improve future incident response.
    24.6k
    repo stars

Frequently asked questions

How do I install the building-incident-response-playbook skill?

Run npx skillmds add mukul975/building-incident-response-playbook in your terminal (requires Node.js), paste this page's agent-chat prompt into Claude, Cursor, or any MCP-connected agent, or download the SKILL.md file and copy it into your agent's skills directory.

What does the building-incident-response-playbook skill do?

Designs and documents structured incident response playbooks aligned with NIST SP 800-61r3 and SANS PICERL frameworks, covering playbook structure, decision trees, escalation criteria, RACI matrices, and SOAR integration. It is listed under Security, Docs & Writing, Incident Response, Technical Writing on SkillMD.

Is building-incident-response-playbook safe to use?

SkillMD's automated safety review verdict for this skill is CAUTION. Independent scanners report: SkillSpector: PASS, Skill Scanner: PASS. Capability flags: executes scripts. SkillMD never runs a skill's scripts for you; review the SKILL.md before installing.

Which AI agents work with building-incident-response-playbook?

This skill is tagged as working with Claude Code, Claude.ai, OpenAI Codex. SKILL.md is an open format, so most agents that read a skills directory can load it too.

Is building-incident-response-playbook free to use?

Yes. Installing skills from SkillMD is free. This skill is licensed under Apache-2.

Who published building-incident-response-playbook?

mukul975 (@mukul975) published this skill. Their other Agent Skills are listed on their SkillMD profile.