Agent skill

Incident Response

by alirezarezvani in alirezarezvani/claude-skills

A skill your agent uses when a security incident has been detected or declared and needs classification, triage, escalation path determination, and forensic evidence collection.

MITAuto-check passedDevOps & Cloud

Install Incident Response

skills CLI
$ npx skills add alirezarezvani/claude-skills --skill incident-response -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install alirezarezvani/claude-skills incident-response --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/alirezarezvani/claude-skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/engineering-team/skills/incident-response .claude/skills/incident-response && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
incident-response
GitHub stars
28k
Token cost
~3.8k tokens
SKILL.md length
1,363 words
Files
3 (incl. scripts, references)
Skills in repo
342
Repo updated
First seen
Licence
MIT

At a glance

A skill your agent uses when a security incident has been detected or declared and needs classification, triage, escalation path determination, and forensic evidence collection.

  • Works in 5 steps: Live memory (RAM dump) — lost on reboot → Running processes and open network… → Logged-in users and active sessions → …
  • A security incident has been detected
  • SKILL.md covers Table of Contents, Overview, Incident Triage Tool and Incident Classification, plus 8 more sections
  • Runs Python scripts from its folder; calls python3 and jq

What it does

Incident Response is an agent skill from alirezarezvani/claude-skills. Use when a security incident has been detected or declared and needs classification, triage, escalation path determination, and forensic evidence collection. Covers SEV1-SEV4 classification, false positive filtering, incident taxonomy, and NIST SP 800-61 lifecycle.

Its SKILL.md is about 3.8k tokens, which your agent loads only when the skill is triggered. The skill folder holds 4 other files, including scripts and reference files (for example `references/regulatory-deadlines.md` and `scripts/incident_triage.py`).

It sits in DevOps & Cloud, covering Incident response, Digital forensics and Security operations. The repository describes itself as: 380 Claude Code skills & agent skills & plugins (30+ Agents, 70+ custom commands, 380+ skills, customizable references, scripts)for Claude Code, Codex, Gemini CLI, Cursor, and 8… The licence is MIT.

When your agent uses it

  • A security incident has been detected
  • Declared and needs classification
  • Escalation path determination
  • Forensic evidence collection

Example prompts

  • “/incident-response”

Requirements

  • Python 3

Workflow steps

5 steps, taken from the first numbered list in SKILL.md.

  1. Live memory (RAM dump) — lost on reboot
  2. Running processes and open network connections (netstat, ps)
  3. Logged-in users and active sessions
  4. System uptime and current time (for timeline anchoring)
  5. Environment variables and loaded kernel modules

What it can do on your machine

Read from SKILL.md and the folder at commit 19392f7. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Ships 1 file in scripts/ (Python), which the agent can run.

    Shell commands in SKILL.md call:

    • python3
    • jq

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Incident Response loads about 3.8k tokens when it runs, and up to ~5.7k if it reads all its reference files. Until then it costs about 71 tokens; SKILL.md has 1,363 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~71
When it runs · the whole SKILL.md, loaded when a task matches
~3.8k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~5.7k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.

SKILL.md

The full file from alirezarezvani/claude-skills at commit 19392f7, republished under its MIT licence (© alirezarezvani). 1,363 words, ~3,836 tokens.

Download SKILL.mdSave it as .claude/skills/incident-response/SKILL.md (or your agent's skills folder). This skill also uses 2 other files; get the full folder from GitHub.
name
incident-response
description
Use when a security incident has been detected or declared and needs classification, triage, escalation path determination, and forensic evidence collection. Covers SEV1-SEV4 classification, false positive filtering, incident taxonomy, and NIST SP 800-61 lifecycle.

Incident Response

Incident response skill for the full lifecycle from initial triage through forensic collection, severity declaration, and escalation routing. This is NOT threat hunting (see threat-detection) or post-incident compliance mapping (see governance/compliance-mapping) — this is about classifying, triaging, and managing declared security incidents.


Table of Contents


Overview

What This Skill Does

This skill provides the methodology and tooling for incident triage and response — classifying security events into typed incidents, scoring severity, filtering false positives, determining escalation paths, and initiating forensic evidence collection under chain-of-custody controls.

Distinction from Other Security Skills
SkillFocusApproach
incident-response (this)Active incidentsReactive — classify, escalate, collect evidence
threat-detectionPre-incident huntingProactive — find threats before alerts fire
cloud-securityCloud posture assessmentPreventive — IAM, S3, network misconfiguration
red-teamOffensive simulationOffensive — test detection and response capability
Prerequisites

A security event must be ingested before triage. Events can come from SIEM alerts, EDR detections, threat intel feeds, or user reports. The triage tool accepts JSON event payloads; see the input schema below.


Incident Triage Tool

The incident_triage.py tool classifies events, checks false positives, scores severity, determines escalation, and performs forensic pre-analysis.

bash
# Classify an event from JSON file
python3 scripts/incident_triage.py --input event.json --classify --json

# Classify with false positive filtering enabled
python3 scripts/incident_triage.py --input event.json --classify --false-positive-check --json

# Force a severity level for tabletop exercises
python3 scripts/incident_triage.py --input event.json --severity sev1 --json

# Read event from stdin
echo '{"event_type": "ransomware", "host": "prod-db-01", "raw_payload": {}}' | \
  python3 scripts/incident_triage.py --classify --false-positive-check --json
Input Event Schema
json
{
  "event_type": "ransomware",
  "host": "prod-db-01",
  "user": "svc_backup",
  "source_ip": "10.1.2.3",
  "timestamp": "2024-01-15T14:32:00Z",
  "raw_payload": {}
}
Exit Codes
CodeMeaningRequired Response
0SEV3/SEV4 or cleanStandard ticket-based handling
1SEV2 — elevated1-hour bridge call, async coordination
2SEV1 — criticalImmediate 15-minute war room, all-hands

Incident Classification

Security events are classified into 14 incident types. Classification drives default severity, MITRE technique mapping, and response SLA.

Incident Taxonomy
Incident TypeDefault SeverityMITRE TechniqueResponse SLA
ransomwareSEV1T148615 minutes
data_exfiltrationSEV1T104815 minutes
apt_intrusionSEV1T156615 minutes
supply_chain_compromiseSEV1T119515 minutes
domain_controller_breachSEV1T1078.00215 minutes
credential_compromiseSEV2T11101 hour
lateral_movementSEV2T10211 hour
malware_infectionSEV2T12041 hour
insider_threatSEV2T10781 hour
cloud_account_compromiseSEV2T1078.0041 hour
unauthorized_accessSEV3T11904 hours
policy_violationSEV3N/A4 hours
phishing_attemptSEV4T1566.00124 hours
security_alertSEV4N/A24 hours
SEV Escalation Triggers

Any of the following automatically re-declare a higher severity:

TriggerNew Severity
Ransomware note foundSEV1
Active exfiltration confirmedSEV1
CloudTrail or SIEM disabledSEV1
Domain controller access confirmedSEV1
Second system compromisedSEV1
Exfiltration volume exceeds 1 GBSEV2 minimum
C-suite account accessedSEV2 minimum

Severity Framework

SEV Level Matrix
LevelNameCriteriaSkills InvokedEscalation Path
SEV1CriticalConfirmed ransomware; active PII/PHI exfiltration (>10K records); domain controller breach; defense evasion (CloudTrail disabled); supply chain compromiseAll skills (parallel)SOC Lead → CISO → CEO → Board Chair
SEV2HighConfirmed unauthorized access to sensitive systems; credential compromise with elevated privileges; lateral movement confirmed; ransomware indicators without confirmed executiontriage + containment + forensicsSOC Lead → CISO
SEV3MediumSuspected unauthorized access (unconfirmed); malware detected and contained; single account compromise (no priv escalation)triage + containmentSOC Lead → Security Manager
SEV4LowSecurity alert with no confirmed impact; informational indicator; policy violation with no data risktriage onlyL3 Analyst queue

False Positive Filtering

The triage tool applies five filters before escalating to prevent false positive inflation.

False Positive Filter Types
FilterDescriptionExample Pattern
CI/CD agent activityKnown build/deploy agents flagged as anomaliesjenkins, github-actions, circleci, gitlab-runner
Test environment taggingAssets tagged as non-productiontest-, staging-, dev-, sandbox-
Scheduled job patternsExpected batch processes triggering alertscron, scheduled_task, batch_job, backup_
Whitelisted identitiesExplicitly approved service accountssvc_monitoring, svc_backup, datadog-agent
Scanner activityKnown security scanners and vulnerability toolsnessus, qualys, rapid7, aws_inspector

A confirmed false positive suppresses escalation and logs the suppression reason for audit purposes. Recurring false positives from the same source should be tuned out at the detection layer, not filtered repeatedly at triage.


Forensic Evidence Collection

Evidence collection follows the DFRWS six-phase framework and the principle of volatile-first acquisition.

DFRWS Six Phases
PhaseActivityPriority
IdentificationIdentify what evidence exists and whereImmediate
PreservationPrevent modification — write-block, snapshot, legal holdImmediate
CollectionAcquire evidence in order of volatilityImmediate
ExaminationTechnical analysis of collected evidenceWithin 2 hours
AnalysisInterpret findings in investigative contextWithin 4 hours
PresentationProduce findings report with chain of custodyBefore incident closure
Volatile Evidence — Collect First
  1. Live memory (RAM dump) — lost on reboot
  2. Running processes and open network connections (netstat, ps)
  3. Logged-in users and active sessions
  4. System uptime and current time (for timeline anchoring)
  5. Environment variables and loaded kernel modules
Chain of Custody Requirements

Every evidence item must be recorded with:

  • SHA-256 hash at acquisition time
  • Acquisition timestamp in UTC with timezone offset
  • Tool provenance (FTK Imager, Volatility, dd, AWS CloudTrail export)
  • Investigator identity
  • Transfer log (who had custody and when)

Escalation Paths

By Severity
SeverityImmediate ContactBridge CallExternal Notification
SEV1SOC Lead + CISO (15 min)Immediate war roomLegal + PR standby; regulatory notification per deadline table
SEV2SOC Lead (30 min async)1-hour bridgeLegal notification if PII involved
SEV3Security Manager (4 hours)Async onlyNone unless scope expands
SEV4L3 Analyst queue (24 hours)NoneNone
Show full SKILL.md (533 more words)Show less
By Incident Type
Incident TypePrimary EscalationSecondary
Ransomware / APTCISO + CEOBoard if data at risk
PII/PHI breachLegal + CISORegulatory body (per deadline table)
Cloud account compromiseCloud security teamCISO
Insider threatHR + Legal + CISOLaw enforcement if criminal
Supply chainCISO + Vendor managementBoard

Regulatory Notification Obligations

The notification clock starts at incident declaration, not at investigation completion.

FrameworkIncident TypeDeadlinePenalty
GDPR (EU 2016/679)Personal data breach72 hours after discoveryUp to 4% global revenue
PCI-DSS v4.0Cardholder data breach24 hours to acquirerCard brand fines
HIPAA (45 CFR 164)PHI breach (>500 individuals)60 days after discoveryUp to $1.9M per violation category
NY DFS 23 NYCRR 500Cybersecurity event72 hours to DFSRegulatory sanctions
SEC Rule (17 CFR 229.106)Material cybersecurity incident4 business days after materiality determinationSEC enforcement
CCPA / CPRABreach of sensitive PIWithout unreasonable delayAG enforcement; private right of action
NIS2 (EU 2022/2555)Significant incident (essential services)24-hour early warning; 72-hour notificationNational authority sanctions

Operational rule: If scope is unclear at declaration, assume the most restrictive applicable deadline and confirm scope within the first response window.

Full deadline reference: references/regulatory-deadlines.md


Workflows

Workflow 1: Quick Triage (15 Minutes)

For single alert requiring classification before escalation decision:

bash
# 1. Classify the event with false positive filtering
python3 scripts/incident_triage.py --input alert.json \
  --classify --false-positive-check --json

# 2. Review severity, escalation_path, and false_positive_flag in output
# 3. If severity = sev1 or sev2, page SOC Lead immediately
# 4. If false_positive_flag = true, document and close

Decision: Exit code 2 = SEV1 war room now. Exit code 1 = SEV2 bridge call within 30 minutes.

Workflow 2: Full Incident Response (SEV1)
T+0   Detection arrives (SIEM alert, EDR, user report)
T+5   Classify with incident_triage.py --classify --false-positive-check
T+10  If SEV1: page CISO, open war room, start regulatory clock
T+15  Initiate forensic collection (volatile evidence first)
T+15  Containment assessment (parallel with forensics)
T+30  Human approval gate for any containment action
T+45  Execute approved containment
T+60  Assess containment effectiveness, brief Legal if PII/PHI scope
T+4h  Final forensic evidence package, dwell time estimate
T+8h  Eradication and recovery plan
T+72h Regulatory notification submission (if GDPR/NIS2 triggered)
bash
# Full classification with forensic context
python3 scripts/incident_triage.py --input incident.json \
  --classify --false-positive-check --severity sev1 --json > incident_triage_output.json

# Forensic pre-analysis
python3 scripts/incident_triage.py --input incident.json --json | \
  jq '.forensic_findings, .chain_of_custody_steps'
Workflow 3: Tabletop Exercise Simulation

Simulate incidents at specific severity levels without real events:

bash
# Simulate SEV1 ransomware incident
echo '{"event_type": "ransomware", "host": "prod-db-01", "user": "svc_backup"}' | \
  python3 scripts/incident_triage.py --classify --severity sev1 --json

# Simulate SEV2 credential compromise
echo '{"event_type": "credential_compromise", "user": "admin_user", "source_ip": "203.0.113.5"}' | \
  python3 scripts/incident_triage.py --classify --false-positive-check --json

# Verify escalation paths for all 14 incident types
for type in ransomware data_exfiltration credential_compromise lateral_movement; do
  echo "{\"event_type\": \"$type\"}" | python3 scripts/incident_triage.py --classify --json
done

Anti-Patterns

  1. Starting the notification clock at investigation completion — Regulatory clocks (GDPR 72 hours, PCI 24 hours) start at discovery, not investigation completion. Declaring late exposes the organization to maximum penalties even if the incident itself was minor.
  2. Containing before collecting volatile evidence — Rebooting or isolating a system destroys RAM, running processes, and active connections. Forensic collection of volatile evidence must happen in parallel with containment, never after.
  3. Skipping false positive verification before escalation — Escalating every alert to SEV1 degrades SOC credibility and causes alert fatigue. Always run false positive filters before paging the CISO.
  4. Undocumented incident command decisions — Every decision made during a SEV1, including decisions made under uncertainty, must be logged in the evidence chain with timestamp and rationale. Undocumented decisions cannot be defended in regulatory investigations.
  5. Treating incident closure as investigation completion — Incidents are closed when eradication and recovery are complete, not when the investigation is done. The forensic report and regulatory submissions may continue after operational closure.
  6. Single-source classification — Classifying an incident from a single data source (one SIEM alert) without corroborating evidence frequently leads to misclassification. Collect at least two independent signals before declaring SEV1.
  7. Bypassing human approval gates for containment — Automated containment actions (network isolation, credential revocation) taken without human approval can cause production outages, destroy evidence, and create liability. Human approval is non-negotiable for all mutating containment actions.

Cross-References

SkillRelationship
threat-detectionConfirmed hunting findings escalate to incident-response for triage and classification
cloud-securityCloud posture findings (IAM compromise, S3 exposure) may trigger incident classification
red-teamRed team findings validate detection coverage; confirmed gaps become hunting hypotheses
security-pen-testingPen test vulnerabilities exploited in the wild escalate to incident-response for active incident handling

© alirezarezvani, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 2 other files (scripts, references) in engineering-team/skills/incident-response of alirezarezvani/claude-skills.

  • SKILL.md
  • references/regulatory-deadlines.md
  • scripts/incident_triage.py

Open the folder on GitHubat commit 19392f7

Compare with similar skills

Incident Response next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Incident Response compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Incident Response this skillalirezarezvani/claude-skills28k—~3.8kAutomated safety check: PassMIT
Forensics OsqueryAgentSecOps/SecOpsAgentKit2201 repos~4.9kAutomated safety check: NotesCustom licence
Ir VelociraptorAgentSecOps/SecOpsAgentKit2201 repos~3.1kAutomated safety check: PassCustom licence
Incident Response NetworkLeoYeAI/openclaw-master-skills2.2k—~5kAutomated safety check: PassApache-2.0
Malware Persistence Analysis with Autorunsmukul975/Anthropic-Cybersecurity-Skills34k—~1.2kAutomated safety check: PassApache-2.0
Implementing Soar Playbook With Palo Alto Xsoarmukul975/Anthropic-Cybersecurity-Skills34k—~2.4kAutomated safety check: PassApache-2.0

Similar skills

  • Forensics Osquery

    AgentSecOps/SecOpsAgentKit

    SQL-powered forensic investigation and system interrogation using osquery to query operating systems as relational databases.

    220 GitHub starsUsed in 1 repo~4.9k tokens
    SecurityAuto-check: notes
  • Ir Velociraptor

    AgentSecOps/SecOpsAgentKit

    Endpoint visibility, digital forensics, and incident response using Velociraptor Query Language (VQL) for evidence collection and threat hunting at scale.

    220 GitHub starsUsed in 1 repo~3.1k tokens
    SecurityAuto-check passed
  • Incident Response Network

    LeoYeAI/openclaw-master-skills

    Network forensics evidence collection and analysis during security incidents.

    2.2k GitHub stars~5k tokensUpdated 2 mo ago
    SecurityAuto-check passed
  • Malware Persistence Analysis with Autoruns

    mukul975/Anthropic-Cybersecurity-Skills

    Hunts Windows malware persistence with Sysinternals Autoruns, covering run keys, services, scheduled tasks and drivers, with baseline comparison.

    34k GitHub stars~1.2k tokensUpdated 1 mo ago
    SecurityAuto-check passed
  • Implementing Soar Playbook With Palo Alto Xsoar

    mukul975/Anthropic-Cybersecurity-Skills

    Build automated incident response playbooks in Cortex XSOAR (Demisto) using its YAML playbook structure, integration commands, and task types to orchestrate phishing, malware, account-compromise…

    34k GitHub stars~2.4k tokensUpdated 1 mo ago
    DevOps & CloudAuto-check passed
  • Conducting Cloud Incident Response

    mukul975/Anthropic-Cybersecurity-Skills

    Respond to security incidents in AWS, Azure, and GCP via identity-based containment, cloud-native log analysis (CloudTrail, Azure Activity Logs, GCP Audit Logs), resource isolation, and forensic…

    34k GitHub stars~3k tokensUpdated 1 mo ago
    DevOps & CloudAuto-check passed

More from alirezarezvani/claude-skills

All 342 skills in this repo
  • Agile Product Owner

    alirezarezvani/claude-skills

    Writes INVEST-checked user stories with acceptance criteria, splits epics, plans sprints from velocity and ranks the backlog with a weighted score.

    28k GitHub starsUsed in 3 repos~3.2k tokens
    Auto-check passed
  • Product Strategist

    alirezarezvani/claude-skills

    OKR cascade toolkit for product leaders: generates aligned company-to-team OKRs from five strategy types and scores how well they line up.

    28k GitHub starsUsed in 2 repos~1.8k tokens
    Auto-check passed
  • App Store Optimization

    alirezarezvani/claude-skills

    App Store Optimization (ASO) toolkit for researching keywords, analyzing competitor rankings, generating metadata suggestions, and improving app visibility on Apple App Store and Google Play Store.

    28k GitHub starsUsed in 1 repo~4.2k tokens
    Auto-check passed
  • AWS Solution Architect

    alirezarezvani/claude-skills

    Design AWS architectures for startups using serverless patterns and IaC templates.

    28k GitHub starsUsed in 1 repo~2.5k tokens
    Auto-check passed
  • Campaign Analytics

    alirezarezvani/claude-skills

    Calculates attribution, funnel and ROI figures for marketing campaigns with three Python scripts that need only the standard library.

    28k GitHub starsUsed in 1 repo~2.1k tokens
    Auto-check passed
  • Code to PRD

    alirezarezvani/claude-skills

    Reverse-engineers a frontend, backend or fullstack codebase into a product requirements document with per-page docs, an enum dictionary and an API inventory.

    28k GitHub starsUsed in 1 repo~4.9k tokens
    Auto-check passed

Questions about Incident Response

What does Incident Response do?

A skill your agent uses when a security incident has been detected or declared and needs classification, triage, escalation path determination, and forensic evidence collection. Incident Response is an agent skill from alirezarezvani/claude-skills. Use when a security incident has been detected or declared and needs classification, triage, escalation path determination, and forensic evidence collection.

When should I use Incident Response?

Incident Response fits situations like: A security incident has been detected; declared and needs classification; escalation path determination; forensic evidence collection.

How do I install Incident Response in Claude Code?

Run `npx skills add alirezarezvani/claude-skills --skill incident-response -a claude-code`. Or copy the skill folder (engineering-team/skills/incident-response in alirezarezvani/claude-skills) into .claude/skills/incident-response in your project. Claude Code loads it when a task matches its description.

How do I install Incident Response in Codex?

Run `npx skills add alirezarezvani/claude-skills --skill incident-response -a codex`. Or copy the skill folder (engineering-team/skills/incident-response in alirezarezvani/claude-skills) into .agents/skills/incident-response in your project. Codex loads it when a task matches its description.

Can I use Incident Response in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add alirezarezvani/claude-skills --skill incident-response -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/incident-response, .gemini/skills/incident-response, .github/skills/incident-response and .opencode/skills/incident-response in your project.

What does Incident Response need to run?

Going by SKILL.md and its folder, Incident Response needs Python for the scripts in its folder and the command-line tools its instructions call (python3 and jq). Our summary lists: Python 3.

Does Incident Response access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Incident Response safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.

What licence does Incident Response use?

Incident Response is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Incident Response use?

About 3.8k tokens (SKILL.md is roughly 15k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 1.9k tokens, read only when the agent opens those files.

What are the alternatives to Incident Response?

Skills that share tags, products or a category with Incident Response: Forensics Osquery (AgentSecOps/SecOpsAgentKit, 220 stars), Ir Velociraptor (AgentSecOps/SecOpsAgentKit, 220 stars), Incident Response Network (LeoYeAI/openclaw-master-skills, 2.2k stars) and Malware Persistence Analysis with Autoruns (mukul975/Anthropic-Cybersecurity-Skills, 34k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Incident Response?

alirezarezvani (a GitHub user) maintains it in alirezarezvani/claude-skills, which has 27,891 GitHub stars. The repository holds 342 skills in this directory. The repository was last updated on August 30, 2026.

Source: alirezarezvani/claude-skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.