Incident Response Bundle | Prompeteer.ai
On-call playbooks, sev-tier definitions, customer comms, postmortems, and remediation-tracking skills.
Included Skills (55)
- Triaging Security Incident With Ir Playbook — Classifies and prioritizes security incidents using structured IR
- Building Incident Response Playbook — Designs and documents structured incident response playbooks with step-by-step
- Building Ransomware Playbook With Cisa Framework — Builds a structured ransomware incident response playbook aligned with
- Conducting Malware Incident Response — The skill guides analysts through a structured malware incident response, identifying the malware family, tracing infection vectors, and assessing the spread across enterprise endpoints. It then directs containment, analysis, eradication, and recovery actions in alignment with MITRE ATT&CK, ensuring a thorough and repeatable response to trojan, worm, ransomware, or other malware outbreaks. This capability benefits security teams that require a systematic, evidence‑based approach to malware triage and endpoint remediation.
- Incident Response Automation — This tool automates production incident management by diagnosing root causes, drafting communications, and generating post-mortem reports to assist SREs during critical system outages.
- Ransomware Response Playbook — This skill generates structured incident response playbooks for SOC teams to effectively detect, contain, and recover from ransomware attacks using industry-standard frameworks.
- Implementing Soar Playbook For Phishing — Automates phishing incident response by calling the Splunk SOAR (Phantom)
- Conducting Phishing Incident Response — The skill enables rapid response to phishing incidents by analyzing reported emails, extracting indicators, sandboxing URLs and attachments, and assessing credential compromise. It quarantines malicious messages across the organization and remediates affected accounts, providing a comprehensive solution for reported phishing, spearphishing, or mailbox-wide purges. This service benefits security teams and IT administrators who must contain threats and protect user credentials efficiently.
- Triaging Security Incident — Performs initial triage of security incidents using the NIST SP
- Building Incident Timeline With Timesketch — Build collaborative forensic incident timelines using Timesketch to ingest,
- Collecting Volatile Evidence From Compromised Host — The skill collects volatile forensic evidence from a compromised host, preserving memory, network connections, running processes, and system state in the correct order of volatility before they are lost. It is used before isolation, shutdown, or remediation, especially when fileless or memory‑resident malware is suspected, root‑cause analysis is required, or evidence must withstand legal scrutiny. The process ensures a documented chain of custody for reliable, admissible findings.
- Building Malware Incident Communication Template — Build structured communication templates for malware incidents (ransomware,
- Building Soc Escalation Matrix — Build a structured SOC escalation matrix defining severity tiers, response
- Vulnerability Prioritization Assistant — This tool helps security professionals calculate and interpret CVSS scores to effectively prioritize vulnerability remediation efforts based on industry-standard risk assessment frameworks.
- Crisis Communication Manager — This skill provides structured workflows, escalation paths, and messaging templates to help incident response teams manage sensitive communications during critical business events.
- Incident Ticketing Integrator — Automates incident lifecycle management by connecting SIEM alerts to ticketing platforms, helping SOC teams streamline tracking, escalation, and compliance documentation.
- Splunk SOAR Automation — This skill helps SOC teams automate alert triage, incident response, and security tool orchestration to reduce manual workload and improve response consistency.
- Conducting Cloud Incident Response — The skill enables rapid containment of cloud security incidents in AWS, Azure, and GCP by isolating compromised resources, applying identity-based controls, and collecting forensic evidence from native logs such as CloudTrail, Azure Activity Logs, and GCP Audit Logs. It is used when CSPM alerts or audit logs reveal compromised credentials, unauthorized IAM changes, or cross-service breaches, allowing security teams to respond swiftly and preserve evidence in transient cloud environments.
- Network Traffic Analyzer — This tool enables cybersecurity professionals to capture and analyze packet data for identifying malicious patterns, diagnosing protocol issues, and supporting incident response investigations.
- Incident Response Dashboard — Creates real-time incident response dashboards in SIEM platforms to provide SOC analysts and leadership with critical situational awareness during active security incidents.
- Performing Cloud Incident Containment Procedures — Execute cloud-native incident containment across AWS, Azure, and GCP using platform
- Detecting Privilege Escalation Attempts — The skill monitors Windows and Linux systems for privilege escalation attempts, such as access token manipulation, UAC bypass, unquoted service path abuse, kernel exploits, and sudo/doas abuse. It supports threat hunters tracking T1068-style attacks, analysts triaging EDR and SIEM alerts on suspicious privilege changes, incident responders scoping compromise, and purple teams validating detection coverage.
- Hunting For Suspicious Scheduled Tasks — The skill identifies adversary persistence and execution through Windows scheduled tasks by analyzing Security Event ID 4698 task‑creation events, suspicious task properties, and unusual execution patterns from schtasks.exe/at.exe. It is employed after detecting schtasks or at.exe in process creation logs, during incident response to enumerate persistence on compromised hosts, or when Event ID 4698 signals an unusual task. This capability benefits security analysts and incident responders seeking to uncover hidden persistence mechanisms.
- Detecting Mimikatz Execution Patterns — The skill detects Mimikatz credential‑dumping by matching command‑line patterns, identifying LSASS access signatures, and spotting known binary or hash indicators, including in‑memory module detection. It is used by threat hunters and incident responders to triage EDR or SIEM alerts, scope compromises, and validate detection coverage during purple‑team exercises. The tool benefits security teams that need precise, actionable evidence of credential‑access activity.
- Hunting For T1098 Account Manipulation — The skill monitors Windows Security Event Log IDs 4738, 4728, 4732, 4756, 4670, and 5136 to detect MITRE ATT&CK T1098 account manipulation, including shadow admin creation, SID history injection, group membership changes, and credential modifications. It is used by security analysts investigating privilege persistence in Active Directory, responding to anomalous group or credential changes, or conducting incident response to trace account tampering.
- Analyzing Ransomware Network Indicators — The skill analyzes Zeek conn.log and NetFlow data to identify ransomware‑related network indicators such as C2 beaconing patterns, TOR exit node connections, data exfiltration flows, and encryption key exchanges. It enables threat hunters to detect active ransomware network activity and assists incident responders investigating pre‑encryption exfiltration.
- Cobalt Strike Analyzer — Extract and analyze Cobalt Strike beacon configurations from files and memory to help incident responders identify C2 infrastructure and attacker tradecraft.
- Network Traffic Forensics — This tool analyzes network traffic captures and flow data to help incident responders identify adversary activity like command-and-control, lateral movement, and data exfiltration.
- Linux Audit Investigator — This tool assists security professionals by analyzing Linux audit logs to detect unauthorized access, privilege escalation, and suspicious system activity for incident response.
- Implementing Vulnerability Sla Breach Alerting — Build an automated SLA breach alerting system for vulnerability remediation,
- Hunting For Shadow Copy Deletion — The skill executes a hypothesis-driven hunt for Volume Shadow Copy deletion (T1490) by querying SIEM/EDR telemetry for vssadmin, wmic shadowcopy, and PowerShell shadow-copy-deletion commands. It is used to detect ransomware preparation or anti-forensics activity, especially after threat intelligence flags active campaigns or when alerts trigger on shadow-copy deletion commands. The approach benefits incident response teams and security analysts by providing precise, actionable evidence of shadow copy tampering.
- Hunting For Startup Folder Persistence — The skill monitors Windows startup directories for suspicious file creation, cross‑references Autoruns entries, and runs a Python watchdog script for real‑time filesystem monitoring. It detects T1547.001 startup folder persistence, enabling security teams to hunt for malware or implants that survive reboot via startup‑folder placement. The tool also validates autoruns and EDR findings against known‑good startup baselines, providing a reliable verification step for incident response.
- Detecting Credential Dumping Techniques — The skill monitors Sysmon Event ID 10 process‑access logs, Windows Security logs, and SIEM correlation rules to detect LSASS credential dumping, SAM database extraction, and NTDS.dit theft, including attacks that use tools such as Mimikatz. It enables security teams to hunt for credential‑theft activity on Windows and Active Directory hosts and to triage EDR alerts related to LSASS access. This capability strengthens incident response by providing precise, actionable detection of advanced credential‑stealing techniques.
- Acquiring Disk Image With Dd And Dcfldd — The skill teaches professionals how to create forensically sound, bit‑for‑bit disk images using dd or dcfldd on a Linux forensic workstation, ensuring evidence integrity through MD5/SHA hash verification. It is essential for investigators imaging suspect drives, USB devices, or memory cards during incident response, or for producing verified copies for legal or law‑enforcement use before any destructive analysis.
- Endpoint Vulnerability Remediation — This skill assists security professionals in prioritizing CVEs and executing automated patch management to maintain endpoint compliance and mitigate critical security risks.
- Analyzing Outlook Pst For Email Forensics — The skill parses Microsoft Outlook PST and OST files with libpff and pst-utils to retrieve message content, headers, attachments, deleted items, and MAPI metadata, including items from the Recoverable Items folder. It reconstructs communication patterns and traces message routing within Outlook archives. Professionals in email forensics, legal e‑discovery, and incident response rely on it to conduct thorough investigations and recover critical data.
- Velociraptor IR Deployment — This skill assists incident responders in deploying and configuring Velociraptor to perform scalable forensic artifact collection and threat hunting across enterprise endpoints.
- Analyzing Campaign Attribution Evidence — The skill systematically evaluates cyber‑campaign evidence to attribute an operation to a threat actor. It applies the Diamond Model and Analysis of Competing Hypotheses to weigh infrastructure overlaps, TTP consistency, malware code similarity, and timing or language artifacts, producing confidence‑weighted attribution assessments. Incident investigators use it to provide a defensible confidence level for attribution decisions.
- Detecting Pass The Hash Attacks — The skill detects Pass‑the‑Hash attacks by analyzing NTLM authentication patterns, flagging Type 3 logons that should use Kerberos, and correlating with credential‑dumping indicators. It is used by threat hunters, incident responders, and security teams to triage suspicious NTLM logons, scope compromises, and validate detection coverage in purple‑team exercises.
- Hunting For Webshell Activity — The skill conducts a hypothesis-driven hunt for web shell deployment on internet-facing servers by scrutinizing file creation in web directories, detecting suspicious child-process spawning from web server processes, and identifying anomalous HTTP request patterns. It is employed after a public-facing application compromise, when EDR or SIEM alerts flag web server anomalies, or during incident response on internet-facing infrastructure. The approach enables security teams to pinpoint hidden web shells and mitigate potential breaches efficiently.
- Hunting For Unusual Service Installations — The skill parses Windows System event log Event ID 7045 to detect suspicious service installations, analyzing binary paths and correlating with Sysmon/EDR telemetry. It flags indicators of persistence mechanisms, enabling security teams to hunt for new-service persistence after a suspected compromise or during incident response. The tool benefits incident responders and threat hunters by providing precise, actionable alerts on service-based persistence on Windows hosts.
- Analyzing Prefetch Files For Execution History — The skill parses Windows Prefetch files (versions 17, 23, 26, and 30) using tools such as PECmd, WinPrefetchView, or python-prefetch to extract program execution history, including run counts, timestamps, and referenced files or DLLs. It enables investigators to build precise execution timelines, confirm whether a suspicious binary executed, and correlate findings with other forensic evidence. This capability serves forensic analysts and incident responders who require accurate, actionable insights into Windows activity.
- Performing Ransomware Tabletop Exercise — Plans and facilitates tabletop exercises simulating ransomware incidents,
- Detecting Email Forwarding Rules Attack — Detect malicious inbox/mail-flow forwarding rules that adversaries create to maintain
- Detecting Lateral Movement With Splunk — Detect adversary lateral movement across networks using Splunk SPL queries
- Analyzing Network Packets With Scapy — The skill teaches professionals to use Scapy for crafting, sending, sniffing, and dissecting TCP, UDP, ICMP, and DNS packets, as well as analyzing pcap files and performing SYN scans. It enables authorized network reconnaissance, protocol-level forensic analysis, and the creation of traffic anomaly detection during security testing. The knowledge benefits network security analysts, penetration testers, and incident responders who need precise packet manipulation and inspection.
- Analyzing Cobaltstrike Malleable C2 Profiles — The skill parses and analyzes Cobalt Strike Malleable C2 profiles using dissect.cobaltstrike and pyMalleableC2, extracting HTTP/DNS transforms, URIs, headers, sleep/jitter, and injection behavior. It then generates network detection signatures that help security teams reverse-engineer captured profiles or build defenses against Beacon traffic. This capability is essential for analysts and incident responders tasked with identifying and mitigating advanced threat activity.
- Building Patch Tuesday Response Process — Establish a repeatable operational process for triaging, testing, and
- Analyzing Email Headers For Phishing Investigation — Parse and analyze email headers (Received chain, Return-Path, Message-ID)
- Analyzing Windows Prefetch With Python — Parse Windows Prefetch (.pf) files with the windowsprefetch Python
- Triaging Windows With Kape — Runs KAPE (Kroll Artifact Parser and Extractor) to collect targeted
- Building Phishing Reporting Button Workflow — Implement a phishing report button (Microsoft 365 built-in Report button
- Rekall Memory Forensics — This tool utilizes the Rekall framework to help security analysts identify malicious artifacts like injected code and hidden processes within Windows memory dumps.
- Detecting Deepfake Audio In Vishing Attacks — The skill detects AI-generated deepfake audio in vishing attacks by extracting spectral features such as MFCC, spectral centroid, spectral contrast, and zero-crossing rate, and classifying samples with machine learning models. It supports batch analysis, confidence scoring, and forensic reporting, enabling investigators and security teams to verify audio authenticity and uncover voice cloning. The solution is ideal for deepfake voice detection, vishing investigations, and AI-generated speech analysis.
- Timestomping Detection Tool — This tool identifies NTFS anti-forensic activity by comparing MFT timestamp attributes to help security analysts detect potential defense evasion techniques.