⚡AgentSkills
🔐 Cybersecurity · Security Incident Response

Execute the first hour of a suspected breach (Ransomware scenario)

Contain, preserve evidence, and communicate without tipping off or destroying forensics.

advanced~30 minSecurity EngineersAppSecDevSecOps

Steps

  1. 1Activate the IR channel; start a timestamped scribe log immediately
  2. 2Preserve evidence BEFORE aggressive remediation (snapshots, memory dumps)
  3. 3Contain: revoke sessions/keys, isolate affected hosts, block indicators
  4. 4Determine blast radius: what data, which accounts, what timeframe
  5. 5Engage legal/compliance early for notification obligations (e.g., 72h GDPR)
  6. 6Brief executives with facts-not-speculation updates hourly
  7. 7Isolate backups and verify offline copies intact before any recovery
  8. 8Never negotiate or pay without legal + law-enforcement consultation

Common Pitfalls

  • ▲Wiping compromised machines destroying evidence
  • ▲Silent handling violating breach-notification laws

Commands

Install with skills CLI
$ npx skills add aniruddhaadak80/skills --skill incident-response-security-breach-first-hour-ransomware
Install globally
$ npx skills add aniruddhaadak80/skills --skill incident-response-security-breach-first-hour-ransomware -g

Tags

#incident-response#forensics#cybersecurity#incident-response-security

Related skills

Technical controls + easy reporting + blameless drills reducing real click-through damage.

🔐 Cybersecurity·~30m