Do not delete the files based on alert severity alone. Severity indicates urgency and impact, not proof. Mark the incident `suspected` (or `blocked` if authorization/scope is missing), preserve originals in place, and record acquisition method, timestamps, hashes, custodian, and original references. Continue safe offline analysis. Any isolation or eradication requires a valid engagement/scope reference, approved operation, named owner, runtime-enforced controls, and independent approval for d...
Installs into .claude/skills of the current project.
Are you the author of Cyber Incident Triage?
Add the live security badge to your README. It updates with every re-scan.
[](https://www.skillsdirectory.com/skills/hoangnguyen0403-cyber-incident-triage-6bc32821)
Do not delete the files based on alert severity alone. Severity indicates urgency and impact, not proof.
Mark the incident `suspected` (or `blocked` if authorization/scope is missing), preserve originals in place, and record acquisition method, timestamps, hashes, custodian, and original references. Continue safe offline analysis.
Any isolation or eradication requires a valid engagement/scope reference, approved operation, named owner, runtime-enforced controls, and independent approval for disruptive containment. Separately authorize containment, eradication, and recovery; never perform production changes from prose alone.