🔐 Cybersecurity · Security Incident Response
Execute the first hour of a suspected breach (Ransomware scenario)
Contain, preserve evidence, and communicate without tipping off or destroying forensics.
advanced~30 minSecurity EngineersAppSecDevSecOps
Steps
- 1Activate the IR channel; start a timestamped scribe log immediately
- 2Preserve evidence BEFORE aggressive remediation (snapshots, memory dumps)
- 3Contain: revoke sessions/keys, isolate affected hosts, block indicators
- 4Determine blast radius: what data, which accounts, what timeframe
- 5Engage legal/compliance early for notification obligations (e.g., 72h GDPR)
- 6Brief executives with facts-not-speculation updates hourly
- 7Isolate backups and verify offline copies intact before any recovery
- 8Never negotiate or pay without legal + law-enforcement consultation
Common Pitfalls
- ▲Wiping compromised machines destroying evidence
- ▲Silent handling violating breach-notification laws
Commands
Install with skills CLI
$ npx skills add aniruddhaadak80/skills --skill incident-response-security-breach-first-hour-ransomwareInstall globally
$ npx skills add aniruddhaadak80/skills --skill incident-response-security-breach-first-hour-ransomware -gTags
#incident-response#forensics#cybersecurity#incident-response-security