Incident Response Bundle
On-call playbooks, sev-tier definitions, customer comms, postmortems, and remediation-tracking skills.
Browse all skill bundles
Included Skills (55)
- Incident Response Architect — Designs structured, compliant incident response playbooks and automated SOAR workflows to help cybersecurity teams standardize their threat detection and mitigation procedures.
- Incident Response Automation — This tool automates production incident management by diagnosing root causes, drafting communications, and generating post-mortem reports to assist SREs during critical system outages.
- Phishing Response Automator — This skill automates phishing incident response by integrating with Splunk SOAR to streamline container creation, artifact management, and playbook execution for security analysts.
- Security Incident Triage — This tool assists security analysts by classifying and prioritizing incoming cyber threats using industry-standard frameworks to streamline incident response workflows.
- Timesketch Timeline Analyzer — This tool enables incident responders to collaboratively ingest, normalize, and analyze multi-source forensic data to reconstruct attack chains and document investigation findings effectively.
- Volatile Evidence Collector — This skill assists incident responders in capturing critical volatile forensic data from compromised hosts to ensure evidence integrity for root cause analysis and legal proceedings.
- Postmortem Documentation Assistant — This tool assists engineering teams in drafting blameless postmortems to facilitate organizational learning and effectively prevent the recurrence of future technical incidents.
- Malware Incident Communicator — This tool generates structured communication templates for malware incidents, assisting cybersecurity teams in streamlining stakeholder notifications, executive briefings, and essential regulatory disclosures.
- Vulnerability Prioritization Assistant — This tool helps security professionals calculate and interpret CVSS scores to effectively prioritize vulnerability remediation efforts based on industry-standard risk assessment frameworks.
- Phishing Triage Automation — This workflow automates the triage, classification, and remediation of user-reported phishing emails to assist security teams in streamlining incident response processes.
- Crisis Communication Manager — This skill provides structured workflows, escalation paths, and messaging templates to help incident response teams manage sensitive communications during critical business events.
- Ransomware Incident Responder — This tool guides cybersecurity professionals through structured ransomware containment, forensic analysis, and recovery processes to mitigate impact and ensure regulatory compliance.
- Splunk SOAR Automation — This skill helps SOC teams automate alert triage, incident response, and security tool orchestration to reduce manual workload and improve response consistency.
- Network Traffic Analyzer — This tool enables cybersecurity professionals to capture and analyze packet data for identifying malicious patterns, diagnosing protocol issues, and supporting incident response investigations.
- Incident Response Dashboard — Creates real-time incident response dashboards in SIEM platforms to provide SOC analysts and leadership with critical situational awareness during active security incidents.
- Incident Response Specialist — This expert SRE tool provides rapid problem resolution, observability guidance, and structured incident management workflows to help engineering teams minimize system downtime.
- Windows Persistence Hunter — This tool systematically identifies adversary persistence mechanisms across Windows endpoints to assist security analysts during incident response and proactive threat hunting operations.
- Cobalt Strike Analyzer — Extract and analyze Cobalt Strike beacon configurations from files and memory to help incident responders identify C2 infrastructure and attacker tradecraft.
- Windows Amcache Analyzer — Parses Windows Amcache registry hives to help digital forensics investigators reconstruct program execution timelines and identify malicious software artifacts during incident response.
- Network Traffic Forensics — This tool analyzes network traffic captures and flow data to help incident responders identify adversary activity like command-and-control, lateral movement, and data exfiltration.
- Linux Audit Investigator — This tool assists security professionals by analyzing Linux audit logs to detect unauthorized access, privilege escalation, and suspicious system activity for incident response.
- Endpoint Vulnerability Remediation — This skill assists security professionals in prioritizing CVEs and executing automated patch management to maintain endpoint compliance and mitigate critical security risks.
- Windows Event Forensics — Analyze Windows Event Logs using specialized tools to detect lateral movement, persistence, and privilege escalation for cybersecurity incident responders and threat hunters.
- Velociraptor IR Deployment — This skill assists incident responders in deploying and configuring Velociraptor to perform scalable forensic artifact collection and threat hunting across enterprise endpoints.
- Ransomware Recovery Orchestrator — This tool automates structured ransomware incident recovery following NIST and CISA frameworks to assist cybersecurity teams in restoring secure, verified infrastructure environments.
- Patch Tuesday Orchestrator — This skill helps security teams establish a repeatable, risk-based workflow for triaging, testing, and deploying Microsoft security updates within strict remediation SLAs.
- Attack Path Analyst — This tool deploys XM Cyber to map complex attack paths and identify critical exposure choke points, helping security teams prioritize effective remediation efforts.
- Windows Forensic Triage — Automates KAPE artifact collection and parsing to assist incident responders in performing rapid, defensible forensic analysis on Windows systems during early containment.
- SIEM Detection Optimizer — This skill helps security operations teams reduce alert fatigue by systematically tuning SIEM detection rules and optimizing thresholds to improve incident response precision.
- Malware Eradication Specialist — This tool assists incident responders in systematically removing malware and persistence mechanisms from compromised systems to restore a secure, clean operational state.
- Windows Prefetch Analyzer — This tool parses Windows Prefetch files to extract execution history and timestamps, assisting forensic investigators in reconstructing program activity during security incident analysis.
- Windows Registry Forensics — Extract and analyze Windows Registry hives to uncover user activity, persistence mechanisms, and system compromise evidence for digital forensics and incident response professionals.
- Windows LNK Analyzer — Extracts target paths and forensic metadata from Windows shortcut files to assist digital investigators in reconstructing user activity and building comprehensive incident timelines.
- Scheduled Task Hunter — This tool facilitates proactive threat hunting for Windows Scheduled Task persistence by guiding security analysts through targeted SIEM and EDR query execution.
- Ransomware Network Analyzer — This skill analyzes Zeek and NetFlow data to help security analysts detect ransomware-related network indicators like C2 beaconing, data exfiltration, and encryption activity.
- Wazuh Detection Engineer — This skill automates Wazuh SIEM deployment, custom rule development, and alert management to help security teams streamline endpoint monitoring and incident response.
- Malware Analysis Expert — This expert assistant provides comprehensive static and dynamic analysis workflows to help security researchers identify threats, extract indicators, and document malicious behavior.
- Memory Forensics Assistant — This skill provides expert guidance and actionable workflows for security professionals to acquire, analyze, and extract critical artifacts from system memory dumps.
- Webshell Threat Hunter — This skill performs hypothesis-driven threat hunting to detect web shell deployment on internet-facing servers, assisting security analysts in identifying unauthorized persistence and malicious activity.
- Rekall Memory Forensics — This tool utilizes the Rekall framework to help security analysts identify malicious artifacts like injected code and hidden processes within Windows memory dumps.
- Suspicious Service Detector — This tool identifies malicious Windows service installations by analyzing Event ID 7045 logs to help security analysts detect persistence and unauthorized system modifications.
- CTI Pattern Extractor — This tool automates the extraction of adversary behaviors from cyber threat intelligence reports to build structured STIX libraries for threat-informed detection engineering.
- DCOM Lateral Movement Hunter — This tool assists security analysts in identifying DCOM-based lateral movement by correlating Sysmon events and network traffic to detect suspicious COM object abuse.
- Timestomping Detection Tool — This tool identifies NTFS anti-forensic activity by comparing MFT timestamp attributes to help security analysts detect potential defense evasion techniques.
- Windows CIS Hardener — This tool helps security administrators harden Windows endpoints by applying CIS benchmark configurations to reduce attack surfaces and ensure regulatory compliance.
- Ransomware Leak Monitor — This tool monitors ransomware data leak sites to extract victim data and generate actionable threat intelligence reports for cybersecurity analysts and risk managers.
- Windows Artifact Analyzer — This tool assists digital forensic investigators by parsing LNK files and Jump Lists to reconstruct user activity, file access, and program execution timelines.
- RBAC Role Optimizer — This tool utilizes clustering and formal concept analysis to help identity administrators consolidate excessive permissions into efficient, least-privilege roles for improved access governance.
- Ransomware Recovery Validator — This tool validates ransomware recovery procedures and backup integrity to help security teams ensure organizational resilience and meet critical RTO and RPO targets.
- Malware Intelligence Analyst — Query the Malpedia API to research malware family lineages, extract YARA detection rules, and map threat actor associations for cybersecurity professionals.
- UEFI Bootkit Analyzer — This tool assists cybersecurity professionals in detecting UEFI firmware implants and persistence mechanisms by leveraging chipsec for comprehensive integrity verification and threat analysis.
- MITRE ATT&CK Threat Modeler — This skill assists SOC teams in mapping adversary TTPs to organizational assets to identify detection gaps and prioritize strategic defensive security investments.
- Ransomware Defense Hardener — Configures Windows Group Policy Objects to block ransomware execution and lateral movement, helping system administrators secure endpoints against sophisticated cyber threats.
- Active Directory Honeytokens — Deploys deception-based honeytokens and monitoring triggers in Active Directory to help security teams detect lateral movement and unauthorized reconnaissance activities.
- USB Forensics Analyzer — This tool reconstructs USB device connection history by correlating Windows registry keys and event logs to assist digital forensic investigators in tracking data exfiltration.