Incident Response

Use when a production incident has been declared and needs classification, triage, escalation, and post-mortem. Covers SEV1-SEV4 severity, false-positive filtering, NIST SP 800-61 lifecycle, and blameless post-mortem facilitation. For proactive threat hunting before an incident fires, use `threat-detection`. For cloud misconfigs, use `cloud-security`.

tmj-90 d67982a 3.7 KB Updated

File contents

tmj-90/gaffer/tree/main/runner/skills/incident-response commit d67982a09b

Frequently asked questions

npx skillmds@latest add tmj-90/incident-response