Do not delete the files based on alert severity. Treat the incident as `suspected` (or `blocked` if authorization/evidence is missing): severity indicates urgency and impact, not proof. Preserve the originals and record acquisition method, timestamps, hashes where available, custodian, and original references. Continue safe offline analysis, documenting the hypothesis and evidence gaps. Containment, eradication, or production changes require an engagement/scope reference, approved operation, ...
Installs into .claude/skills of the current project.
Are you the author of Cyber Incident Triage?
Add the live security badge to your README. It updates with every re-scan.
[](https://www.skillsdirectory.com/skills/hoangnguyen0403-cyber-incident-triage-agent-skills-standard)
Do not delete the files based on alert severity. Treat the incident as `suspected` (or `blocked` if authorization/evidence is missing): severity indicates urgency and impact, not proof.
Preserve the originals and record acquisition method, timestamps, hashes where available, custodian, and original references. Continue safe offline analysis, documenting the hypothesis and evidence gaps.
Containment, eradication, or production changes require an engagement/scope reference, approved operation, designated owner, and runtime-proven controls; disruptive containment also requires independent approval. Keep analysis separate from containment, eradication, and recovery. The next approved action should be evidence-preserving collection or authorized isolation—not deletion.