Skip to content
Back to skills

Triage Security Incident

ASecurity

Triage a suspected incident across endpoints, identities, applications, cloud resources, networks, or data. Use when an alert, compromise, disruption, unauthorized access, malware, credential concern, or exposure needs scope and ownership.

  • 7 stars
  • 0 votes
  • 0 copies
  • 1 view
  • Added September 5, 2026
ai-agentsgosecurity

Security analysis

A100/100

Pro scans all 3 files and shows the line behind each finding

Scanned September 5, 2026

npx -y skills add gaelic-ghost/socket --skill triage-security-incident --agent claude-code

Installs into .claude/skills of the current project.

Are you the author of Triage Security Incident?

Add the live security badge to your README. It updates with every re-scan.

Security grade badge for Triage Security Incident
[![Security: A — Skills Directory](https://www.skillsdirectory.com/api/skills/gaelic-ghost-triage-security-incident/badge)](https://www.skillsdirectory.com/skills/gaelic-ghost-triage-security-incident)

More formats (shields.io, HTML) on the badges page. Keep it an A: scan every change in CI with Pro.

Download with Pro
SKILL.md
---
name: triage-security-incident
description: Triage a suspected incident across endpoints, identities, applications, cloud resources, networks, or data. Use when an alert, compromise, disruption, unauthorized access, malware, credential concern, or exposure needs scope and ownership.
---

# Triage Security Incident

## Overview

Establish whether coordinated response is needed, what may be affected, and who owns decisions. Preserve uncertainty and avoid destructive cleanup while urgent harm reduction and evidence collection are balanced.

Read [references/incident-triage-record.md](references/incident-triage-record.md) for the initial record aligned with current NIST incident-response guidance.

## Workflow

1. Open the incident record.
   - Record reporter, detection source, time/timezone, symptoms, affected person/system, current status, and incident lead.
2. Validate the signal.
   - Preserve the original alert/report and confirm artifact, account, host, service, or event identity.
   - Separate direct observation, external intelligence, automation labels, and speculation.
3. Estimate scope and urgency.
   - Identify potentially affected assets, identities, data, users, environments, business function, privileges, and time window.
   - Record ongoing execution, access, exfiltration, destruction, fraud, safety, or service impact.
4. Decide immediate harm reduction.
   - Choose reversible isolation, session/token revocation, feature disablement, traffic control, or monitoring only when evidence and authority justify it.
   - State evidence loss and operational impact.
5. Preserve priority evidence.
   - Capture volatile state, logs, artifacts, identity/provider records, application events, network evidence, and timeline sources proportionately.
6. Establish coordination.
   - Name technical, business, legal/privacy, communications, vendor/provider, and affected-user contacts as applicable; keep sensitive details need-to-know.
7. Route the next phase.
   - Use containment for ongoing harm, hunting for scope, specialist analysis for evidence, and recovery only after eradication criteria are defined.

## Output

Return incident identity/owner, signal confidence, affected/potential scope, urgency, immediate actions, evidence plan, contacts, open questions, and next phase.

Files in this skill

  • SKILL.md2.3 KB
  • agents/openai.yaml245 B
  • references/incident-triage-record.md763 B

Attribution

Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.

Comments

Loading comments…