Agent skill

Incident Triage

by briiirussell in briiirussell/cybersecurity-skills

Guide rapid triage and initial response to security incidents following NIST SP 800-61 methodology.

MITAuto-check: notesSecurity

Install Incident Triage

skills CLI
$ npx skills add briiirussell/cybersecurity-skills --skill incident-triage -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install briiirussell/cybersecurity-skills incident-triage --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/briiirussell/cybersecurity-skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/incident-triage .claude/skills/incident-triage && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
incident-triage
GitHub stars
413
Token cost
~1.5k tokens
SKILL.md length
487 words
Files
1
Skills in repo
25
Repo updated
First seen
Licence
MIT

At a glance

Guide rapid triage and initial response to security incidents following NIST SP 800-61 methodology.

  • Works in 5 steps: Classification → Initial Containment → Evidence Preservation → …
  • The user mentions incident response
  • SKILL.md covers Priorities (in order), Step 1: Classification, Step 2: Initial Containment and Step 3: Evidence Preservation, plus 5 more sections
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md

What it does

Incident Triage is an agent skill from briiirussell/cybersecurity-skills. Guide rapid triage and initial response to security incidents following NIST SP 800-61 methodology. Use when the user mentions 'incident response,' 'security incident,' 'triage,' 'we've been hacked,' 'breach,' 'compromised,' 'malware detected,' 'suspicious activity,' 'IOC,' 'indicators of compromise,' or needs help handling a security event.

Its SKILL.md is about 1.5k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Security, covering Security operations and Incident response. The repository describes itself as: Cybersecurity skills for AI coding agents (Claude Code, Cursor, Codex). The licence is MIT.

When your agent uses it

  • The user mentions incident response
  • Security incident
  • Weve been hacked
  • Malware detected

Example prompts

  • “incident response,”
  • “security incident,”
  • “triage,”
  • “/incident-triage”

Requirements

  • Pre-approved tools (allowed-tools): Bash, Read, Write, Grep, Glob, WebSearch

Workflow steps

5 steps, taken from the step headings in SKILL.md.

  1. Classification
  2. Initial Containment
  3. Evidence Preservation
  4. Initial Analysis
  5. IOC Extraction

What it can do on your machine

Read from SKILL.md and the folder at commit c9ade03. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves these tools, so the agent can use them without asking each time:

    • Bash
    • Read
    • Write
    • Grep
    • Glob
    • WebSearch

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md (its code samples are bash and markdown).

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Incident Triage loads about 1.5k tokens when it runs. Until then it costs about 90 tokens; SKILL.md has 487 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~90
When it runs · the whole SKILL.md, loaded when a task matches
~1.5k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check: notes

The automated check noted patterns worth knowing about, such as sudo or a known installer.

  • NotePre-approves every shell command (allowed-tools: Bash)SKILL.md
    allowed-tools: Bash, Read, Write, Grep, Glob, WebSearch

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from briiirussell/cybersecurity-skills at commit c9ade03, republished under its MIT licence (© briiirussell). 487 words, ~1,485 tokens.

Download SKILL.mdSave it as .claude/skills/incident-triage/SKILL.md (or your agent's skills folder).
name
incident-triage
description
Guide rapid triage and initial response to security incidents following NIST SP 800-61 methodology. Use when the user mentions 'incident response,' 'security incident,' 'triage,' 'we've been hacked,' 'breach,' 'compromised,' 'malware detected,' 'suspicious activity,' 'IOC,' 'indicators of compromise,' or needs help handling a security event.
allowed-tools
Bash, Read, Write, Grep, Glob, WebSearch

Incident Triage — Security Incident Response

Guide rapid triage and initial response to security incidents. Follow NIST SP 800-61 methodology.

Cross-references: siem-detection for the rules that produced the alert this triage is responding to, disk-forensics for deeper disk and memory analysis once a host is contained, breach-patterns for the post-incident pattern extraction that hardens against recurrence, soc-operations for the operational layer above this skill (runbooks, escalation, handoff), security-comms for the stakeholder / customer notifications the response generates, privacy-engineering / hipaa-audit / pci-audit for the regulatory-clock determination when personal data, PHI, or cardholder data is involved, ai-risk-management for AI-specific incident classes (model failure, fairness drift, jailbreak exploitation in production).

Priorities (in order)

  1. Preserve human safety
  2. Contain the incident to prevent further damage
  3. Preserve evidence for investigation
  4. Identify root cause and scope
  5. Document everything

Step 1: Classification

Determine incident type:

  • Malware: ransomware, trojan, worm, cryptominer
  • Unauthorized access: compromised credentials, exploitation
  • Data exfiltration: data theft, insider threat
  • Denial of service
  • Web compromise: defacement, skimming, backdoor
  • Phishing / social engineering

Determine severity:

  • Critical: active data exfiltration, ransomware spreading, critical system compromise
  • High: confirmed compromise, malware detected, unauthorized access
  • Medium: suspicious activity, potential indicators, failed attacks
  • Low: policy violation, reconnaissance detected, likely false positive

Step 2: Initial Containment

Based on type and severity:

  • Network: block suspicious IPs/domains at firewall
  • Host: isolate affected system (network disconnect, NOT power off — volatile memory is evidence)
  • Account: disable compromised accounts, force password resets
  • Application: disable affected service if safe to do so

Critical: Do NOT power off systems. Volatile memory contains evidence.

Step 3: Evidence Preservation

Capture in order of volatility (most volatile first):

bash
# 1. Running processes
ps auxf                         # Linux
tasklist /v                     # Windows

# 2. Network connections
ss -tupn                        # Linux
netstat -anob                   # Windows

# 3. Logged-in users
who -a                          # Linux
query user                      # Windows

# 4. Open files
lsof -nP                        # Linux

# 5. System logs
journalctl --since "1 hour ago" # Linux/systemd

If memory forensics tools are available (LiME, WinPmem), capture a memory dump before anything else.

Show full SKILL.md (207 more words)Show less

Step 4: Initial Analysis

For each suspicious indicator, document:

  • What: describe the artifact
  • When: timestamps in UTC
  • Where: affected system(s)
  • How: how it was detected

Common analysis:

  • Process tree: look for unusual process names, paths, or parent-child relationships
  • Network indicators: unusual outbound connections, DNS queries to suspicious domains, beaconing patterns (regular intervals)
  • File indicators: recently modified files in unusual locations, hidden files, new executables
  • Log analysis: authentication failures, privilege escalation, service changes, cleared logs
  • Persistence: crontab, systemd units, registry Run keys, scheduled tasks, startup items

Step 5: IOC Extraction

Extract and document all indicators of compromise:

TypeExamples
IP addressesSource and destination IPs
DomainsC2 domains, phishing domains
File hashesMD5 and SHA256 of suspicious files
File pathsMalware locations, dropped files
Email addressesPhishing sender addresses
URLsMalicious URLs, C2 endpoints
User agentsUnusual or known-malicious user agents

Output Format

markdown
# Incident Triage Report
## Incident ID: [ID]
## Date/Time: [UTC]
## Severity: [Critical/High/Medium/Low]
## Classification: [incident type]
## Status: [Triage/Contained/Analyzing/Resolved]

### Summary
[2-3 sentence overview]

### Affected Systems
| Hostname | IP | Role | Status |
|----------|-----|------|--------|

### Timeline
| Time (UTC) | Event | Source | Notes |
|------------|-------|--------|-------|

### Indicators of Compromise
| Type | Value | Context | Confidence |
|------|-------|---------|------------|

### Containment Actions Taken
- [ ] [Action and result]

### Evidence Preserved
| Type | Location | Hash | Notes |
|------|----------|------|-------|

### Recommended Next Steps
1. [Immediate priority]
2. [Short-term action]
3. [Follow-up investigation]

### Escalation Checklist
- [ ] Management notified
- [ ] Legal notified (if data breach)
- [ ] Law enforcement (if applicable)
- [ ] Affected parties notified (if data breach)

Boundaries

  • Focus on defense and containment, not counter-attack
  • Preserve evidence — never modify logs or timestamps
  • Recommend legal/management escalation for confirmed breaches
  • If unsure about a containment action's impact, advise caution and ask
  • Never recommend "hacking back" or retaliatory actions
  • Refuse requests to cover up incidents or tamper with evidence

References

  • NIST SP 800-61r2: Computer Security Incident Handling Guide
  • SANS Incident Handler's Handbook
  • MITRE ATT&CK Framework

© briiirussell, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in skills/incident-triage of briiirussell/cybersecurity-skills.

Open the folder on GitHubat commit c9ade03

Compare with similar skills

Incident Triage next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Incident Triage compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Incident Triage this skillbriiirussell/cybersecurity-skills413—~1.5kAutomated safety check: NotesMIT
Hunting For Webshell Activitymukul975/Anthropic-Cybersecurity-Skills34k—~904Automated safety check: PassApache-2.0
Detecting Network Anomalies With Zeekmukul975/Anthropic-Cybersecurity-Skills34k—~3.6kAutomated safety check: NotesApache-2.0
Implementing Soar Automation With Phantommukul975/Anthropic-Cybersecurity-Skills34k—~3.6kAutomated safety check: PassApache-2.0
Hunting For Unusual Service Installationsmukul975/Anthropic-Cybersecurity-Skills34k—~677Automated safety check: PassApache-2.0
Breach Detection Systemmukul975/Privacy-Data-Protection-Skills301—~3kAutomated safety check: PassApache-2.0

Similar skills

  • Hunting For Webshell Activity

    mukul975/Anthropic-Cybersecurity-Skills

    Runs a hypothesis-driven threat hunt for web shell deployment (T1505.003) on internet-facing servers by analyzing file creation in web directories, suspicious child-process spawning from web server…

    34k GitHub stars~904 tokensUpdated 1 mo ago
    SecurityAuto-check passed
  • Detecting Network Anomalies With Zeek

    mukul975/Anthropic-Cybersecurity-Skills

    Deploy and configure Zeek (formerly Bro) to passively analyze network traffic, generate structured connection/DNS/HTTP/SSL/file logs, detect anomalous behavior, and write custom scripts for…

    34k GitHub stars~3.6k tokensUpdated 1 mo ago
    SecurityAuto-check: notes
  • Implementing Soar Automation With Phantom

    mukul975/Anthropic-Cybersecurity-Skills

    Implements Security Orchestration, Automation, and Response (SOAR) workflows using Splunk SOAR (formerly Phantom) to automate alert triage, IOC enrichment, containment actions, and incident response…

    34k GitHub stars~3.6k tokensUpdated 1 mo ago
    SecurityAuto-check passed
  • Hunting For Unusual Service Installations

    mukul975/Anthropic-Cybersecurity-Skills

    Detects suspicious Windows service installations (MITRE ATT&CK T1543.003) by parsing System event log Event ID 7045, analyzing service binary paths, and flagging indicators of persistence mechanisms…

    34k GitHub stars~677 tokensUpdated 1 mo ago
    SecurityAuto-check passed
  • Breach Detection System

    mukul975/Privacy-Data-Protection-Skills

    Implements technical breach detection capabilities including SIEM integration, DLP alert configuration, anomaly detection rules, and insider threat monitoring.

    301 GitHub stars~3k tokensUpdated 6 mo ago
    SecurityAuto-check passed
  • Sentinel

    vinayaklatthe/microsoft-security-skills

    Guidance for designing and operating Microsoft Sentinel, the cloud-native SIEM and SOAR delivered through the Defender portal.

    175 GitHub stars~2.2k tokensUpdated 3 mo ago
    SecurityAuto-check passed

More from briiirussell/cybersecurity-skills

All 25 skills in this repo
  • AI Risk Management

    briiirussell/cybersecurity-skills

    Apply the NIST AI Risk Management Framework (AI RMF 1.0) and adjacent guidance to AI / ML systems — model lifecycle governance, fairness and bias evaluation, robustness, transparency…

    413 GitHub stars~3.7k tokensUpdated 4 mo ago
    Auto-check: notes
  • API Audit

    briiirussell/cybersecurity-skills

    Audit REST, GraphQL, and RPC APIs against the OWASP API Security Top 10 (2023).

    413 GitHub stars~2.8k tokensUpdated 4 mo ago
    Auto-check: notes
  • Breach Patterns

    briiirussell/cybersecurity-skills

    Learn from public breach disclosures — extract the audit question each one implies and check your own stack.

    413 GitHub stars~3.5k tokensUpdated 4 mo ago
    Auto-check: notes
  • Cloud Audit

    briiirussell/cybersecurity-skills

    Audit cloud infrastructure (AWS, GCP, Azure) for misconfigurations, excessive permissions, and security gaps.

    413 GitHub stars~1.3k tokensUpdated 4 mo ago
    Auto-check: notes
  • Container Audit

    briiirussell/cybersecurity-skills

    Audit container images, Dockerfiles, and Kubernetes manifests for misconfigurations, excessive privileges, exposed secrets, and runtime risks.

    413 GitHub stars~2.5k tokensUpdated 4 mo ago
    Auto-check: notes
  • Crypto Audit

    briiirussell/cybersecurity-skills

    Audit cryptography implementation — algorithm choice, key sizes, KDF parameters, IV/nonce handling, signature verification, randomness, TLS configuration, and key rotation.

    413 GitHub stars~2.8k tokensUpdated 4 mo ago
    Auto-check: notes

Questions about Incident Triage

What does Incident Triage do?

Guide rapid triage and initial response to security incidents following NIST SP 800-61 methodology. Incident Triage is an agent skill from briiirussell/cybersecurity-skills. Guide rapid triage and initial response to security incidents following NIST SP 800-61 methodology.

When should I use Incident Triage?

Incident Triage fits situations like: the user mentions incident response; security incident; weve been hacked; malware detected.

How do I install Incident Triage in Claude Code?

Run `npx skills add briiirussell/cybersecurity-skills --skill incident-triage -a claude-code`. Or copy the skill folder (skills/incident-triage in briiirussell/cybersecurity-skills) into .claude/skills/incident-triage in your project. Claude Code loads it when a task matches its description.

How do I install Incident Triage in Codex?

Run `npx skills add briiirussell/cybersecurity-skills --skill incident-triage -a codex`. Or copy the skill folder (skills/incident-triage in briiirussell/cybersecurity-skills) into .agents/skills/incident-triage in your project. Codex loads it when a task matches its description.

Can I use Incident Triage in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add briiirussell/cybersecurity-skills --skill incident-triage -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/incident-triage, .gemini/skills/incident-triage, .github/skills/incident-triage and .opencode/skills/incident-triage in your project.

What does Incident Triage need to run?

SKILL.md names no scripts, command-line tools or credentials: Incident Triage is instructions for the agent only. Its frontmatter pre-approves these tools: Bash, Read, Write, Grep, Glob, WebSearch.

Does Incident Triage access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Incident Triage safe to install?

Our automated static check of SKILL.md found notes only (pre-approves every shell command (allowed-tools: bash)), nothing it rates as a warning. It is not a guarantee. Review the folder before installing.

What licence does Incident Triage use?

Incident Triage is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Incident Triage use?

About 1.5k tokens (SKILL.md is roughly 5.9k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Incident Triage?

Skills that share tags, products or a category with Incident Triage: Hunting For Webshell Activity (mukul975/Anthropic-Cybersecurity-Skills, 34k stars), Detecting Network Anomalies With Zeek (mukul975/Anthropic-Cybersecurity-Skills, 34k stars), Implementing Soar Automation With Phantom (mukul975/Anthropic-Cybersecurity-Skills, 34k stars) and Hunting For Unusual Service Installations (mukul975/Anthropic-Cybersecurity-Skills, 34k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Incident Triage?

briiirussell (a GitHub user) maintains it in briiirussell/cybersecurity-skills, which has 413 GitHub stars. The repository holds 25 skills in this directory. The repository was last updated on May 27, 2026.

Source: briiirussell/cybersecurity-skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.