Agent skill

Building Incident Response Playbook

by mukul975 in mukul975/Anthropic-Cybersecurity-Skills

Designs and documents structured incident response playbooks with step-by-step procedures per incident type, decision trees, escalation criteria, RACI matrices, and SOAR platform integration…

Apache-2.0Auto-check passedDevOps & Cloud

Install Building Incident Response Playbook

skills CLI
$ npx skills add mukul975/Anthropic-Cybersecurity-Skills --skill building-incident-response-playbook -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install mukul975/Anthropic-Cybersecurity-Skills building-incident-response-playbook --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/mukul975/Anthropic-Cybersecurity-Skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/building-incident-response-playbook .claude/skills/building-incident-response-playbook && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
building-incident-response-playbook
GitHub stars
34k
Token cost
~2.6k tokens
SKILL.md length
740 words
Files
4 (incl. scripts, references)
Skills in repo
644
Repo updated
First seen
Licence
Apache-2.0

At a glance

Designs and documents structured incident response playbooks with step-by-step procedures per incident type, decision trees, escalation criteria, RACI matrices, and SOAR platform integration…

  • Works in 6 steps: Select and Scope the Incident Type → Define the Playbook Structure → Write Decision Trees and Escalation… → …
  • Maturing an IR program
  • SKILL.md covers When to Use, Prerequisites, Workflow and Key Concepts, plus 3 more sections
  • Runs Python scripts from its folder

What it does

Building Incident Response Playbook is an agent skill from mukul975/Anthropic-Cybersecurity-Skills. Designs and documents structured incident response playbooks with step-by-step procedures per incident type, decision trees, escalation criteria, RACI matrices, and SOAR platform integration, aligned to NIST SP 800-61r3 and SANS PICERL. Use when creating or maturing an IR program, documenting response runbooks for a new incident type, or designing SOAR playbooks.

Its SKILL.md is about 2.6k tokens, which your agent loads only when the skill is triggered. The skill folder holds 5 other files, including scripts and reference files (for example `references/api-reference.md` and `scripts/agent.py`).

It sits in DevOps & Cloud, covering Incident response and Runbooks and postmortems. The repository describes itself as: 817 structured cybersecurity skills for AI agents · Mapped to 6 frameworks: MITRE ATT&CK, NIST CSF 2.0, MITRE ATLAS, D3FEND, NIST AI RMF & MITRE F3 (Fight Fraud) · agentskills.io…. The licence is Apache-2.0.

When your agent uses it

  • Maturing an IR program
  • Documenting response runbooks for a new incident type
  • Designing SOAR playbooks

Example prompts

  • “Use the building-incident-response-playbook skill to design and documents structured incident response playbooks with step-by-step procedures per…”
  • “/building-incident-response-playbook”

Requirements

  • Python 3

Workflow steps

6 steps, taken from the step headings in SKILL.md.

  1. Select and Scope the Incident Type
  2. Define the Playbook Structure
  3. Write Decision Trees and Escalation Criteria
  4. Define Specific Technical Procedures
  5. Integrate with SOAR Platform
  6. Test and Maintain the Playbook

What it can do on your machine

Read from SKILL.md and the folder at commit 54a7988. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Ships 1 file in scripts/ (Python), which the agent can run.

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Building Incident Response Playbook loads about 2.6k tokens when it runs, and up to ~3.2k if it reads all its reference files. Until then it costs about 100 tokens; SKILL.md has 740 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~100
When it runs · the whole SKILL.md, loaded when a task matches
~2.6k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~3.2k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.

SKILL.md

The full file from mukul975/Anthropic-Cybersecurity-Skills at commit 54a7988, republished under its Apache-2.0 licence (© mukul975). 740 words, ~2,561 tokens.

Download SKILL.mdSave it as .claude/skills/building-incident-response-playbook/SKILL.md (or your agent's skills folder). This skill also uses 3 other files; get the full folder from GitHub.
name
building-incident-response-playbook
description
Designs and documents structured incident response playbooks with step-by-step procedures per incident type, decision trees, escalation criteria, RACI matrices, and SOAR platform integration, aligned to NIST SP 800-61r3 and SANS PICERL. Use when creating or maturing an IR program, documenting response runbooks for a new incident type, or designing SOAR playbooks.
domain
cybersecurity
subdomain
incident-response
tags
IR-playbook, runbook, NIST-800-61, SOAR-integration, response-procedures
mitre_attack
T1486, T1566, T1190, T1041, T1078
version
1.0.0
author
mahipal
license
Apache-2.0
nist_csf
RS.MA-01, RS.MA-02, RS.AN-03, RC.RP-01

Building Incident Response Playbooks

When to Use

  • Establishing or maturing an incident response program from scratch
  • Documenting procedures for a new incident type after a novel attack
  • Automating response workflows in a SOAR platform (Cortex XSOAR, Splunk SOAR)
  • Preparing for compliance audits requiring documented IR procedures (SOC 2, PCI-DSS, HIPAA)
  • Conducting a gap analysis of existing IR capabilities against specific threat scenarios

Do not use for one-time ad hoc investigations; playbooks are reusable procedure documents, not case-specific reports.

Prerequisites

  • Organizational risk assessment identifying top incident scenarios by likelihood and impact
  • NIST SP 800-61r3 or SANS PICERL framework adopted as the organizational IR standard
  • Asset inventory with business criticality ratings and data classification
  • RACI chart defining roles: Incident Commander, SOC analysts, system administrators, legal, communications
  • Existing detection capabilities inventory (SIEM rules, EDR detections, IDS signatures)
  • SOAR platform access if building automated playbooks

Workflow

Step 1: Select and Scope the Incident Type

Define the specific scenario the playbook will address:

  • Identify the top incident types based on organizational risk assessment and historical data
  • Scope each playbook to a single incident type for clarity (do not combine unrelated scenarios)
  • Define trigger conditions that activate the playbook

Common playbook types:

Priority Playbooks (build first):
1. Ransomware incident response
2. Phishing/credential compromise
3. Business email compromise
4. Malware infection
5. Data breach/exfiltration
6. DDoS attack
7. Insider threat
8. Account takeover
9. Web application compromise
10. Cloud infrastructure compromise
Step 2: Define the Playbook Structure

Every playbook should follow a consistent structure:

PLAYBOOK TEMPLATE
━━━━━━━━━━━━━━━━
1. Playbook Metadata
   - Name, version, owner, last review date
   - Trigger conditions
   - Severity criteria

2. RACI Matrix
   - Who is Responsible, Accountable, Consulted, Informed for each step

3. Detection & Triage
   - How the incident is detected
   - Initial triage checklist
   - Severity classification criteria

4. Containment
   - Short-term containment actions
   - Long-term containment actions
   - Evidence preservation requirements

5. Eradication
   - Root cause identification
   - Malware/threat removal steps
   - Verification procedures

6. Recovery
   - System restoration steps
   - Validation criteria
   - Monitoring requirements post-recovery

7. Post-Incident
   - Lessons learned meeting trigger
   - Report template
   - Detection improvement actions

8. Communication
   - Internal notification matrix
   - External notification requirements (regulators, customers, law enforcement)
   - Status update cadence

9. Appendices
   - Tool-specific procedures
   - Contact lists
   - Evidence collection checklists
Step 3: Write Decision Trees and Escalation Criteria

Define clear decision points with binary outcomes:

Detection Alert Received
├── Is the alert a true positive?
│   ├── YES → Classify severity
│   │   ├── P1 (Critical) → Page incident commander, begin containment immediately
│   │   ├── P2 (High) → Notify IR lead, begin investigation within 30 min
│   │   ├── P3 (Medium) → Queue for investigation within 4 hours
│   │   └── P4 (Low) → Document and investigate within 24 hours
│   └── NO → Document as false positive, tune detection rule
└── Cannot determine → Escalate to Tier 2 for deeper analysis

Escalation triggers:

  • Any P1 incident: Immediate escalation to IR lead and CISO
  • Data exfiltration confirmed: Legal counsel and privacy officer notified
  • Customer data involved: Customer notification process activated
  • Third-party involvement: Vendor security contact engaged
  • Law enforcement needed: General counsel authorizes before contact
Step 4: Define Specific Technical Procedures

Write tool-specific instructions for each step (not generic guidance):

CONTAINMENT - Endpoint Isolation via CrowdStrike:
1. Open Falcon Console > Hosts > Search for affected hostname
2. Click on the host > Host Details
3. Click "Contain Host" button in upper right
4. Confirm isolation (host will only communicate with CrowdStrike cloud)
5. Document containment action in incident ticket with timestamp
6. Verify containment: Host should show "Contained" status badge

CONTAINMENT - Block C2 Domain at DNS:
1. SSH to DNS server: ssh admin@dns-primary.corp.local
2. Add to block zone: echo "zone evil.com { type master; file /etc/bind/db.sinkhole; };" >> /etc/bind/named.conf.local
3. Reload DNS: rndc reload
4. Verify: dig @dns-primary evil.com (should resolve to sinkhole IP 10.0.0.99)
5. Document blocked domain in incident ticket
Step 5: Integrate with SOAR Platform

Convert manual playbook steps into automated workflows:

  • Map each playbook step to a SOAR action (API call, script, human decision point)
  • Define automation boundaries (what runs automatically vs. what requires analyst approval)
  • Build enrichment automations for the triage phase
  • Create containment automations with approval gates for high-impact actions
  • Configure notification automations for stakeholder communication
Step 6: Test and Maintain the Playbook

Validate the playbook through exercises and maintain currency:

  • Conduct tabletop exercises with the IR team walking through the playbook
  • Perform live-fire exercises simulating the incident type in a test environment
  • Review and update after every real incident that uses the playbook
  • Schedule quarterly reviews for accuracy of contact lists, tool procedures, and escalation paths
  • Track playbook metrics: mean time to contain, mean time to resolve, false positive rate
Show full SKILL.md (324 more words)Show less

Key Concepts

TermDefinition
PlaybookDocumented, repeatable set of procedures for responding to a specific incident type
RunbookMore granular than a playbook; step-by-step technical instructions for a specific task within a playbook
RACI MatrixResponsibility assignment chart defining who is Responsible, Accountable, Consulted, and Informed for each activity
Decision TreeFlowchart-based logic defining the response path based on binary conditions at each decision point
Escalation CriteriaPredefined conditions that trigger notification of higher-level personnel or external parties
SOAR PlaybookAutomated workflow in a Security Orchestration, Automation, and Response platform executing playbook steps

Tools & Systems

  • Cortex XSOAR: SOAR platform with visual playbook editor, 700+ integrations, and collaborative War Room
  • Splunk SOAR: SOAR platform integrated with Splunk ES, drag-and-drop playbook builder with 2,800+ automated actions
  • TheHive: Open-source incident response platform with case templates that function as playbook frameworks
  • Confluence / GitLab Wiki: Documentation platforms for maintaining human-readable playbook documents with version control
  • Tines: No-code security automation platform for building playbook workflows without programming

Common Scenarios

Scenario: Building a Phishing Response Playbook from Scratch

Context: An organization with a 5-person SOC has no documented phishing response procedure. Analysts handle phishing reports inconsistently.

Approach:

  1. Interview SOC analysts to document their current ad hoc process
  2. Define the trigger: user reports phishing email via abuse@ mailbox or phishing button
  3. Write triage steps: extract email headers, check sender reputation, analyze URLs/attachments in sandbox
  4. Define containment: quarantine email from all mailboxes, block sender domain, reset passwords if credentials entered
  5. Build SOAR automation: auto-extract IOCs from reported email, enrich via VirusTotal, create case in TheHive
  6. Test with simulated phishing email and measure response time improvement

Pitfalls:

  • Writing overly generic procedures that don't reference specific tool interfaces or commands
  • Not including the communication plan for notifying users who received the phishing email
  • Forgetting to define the criteria for when a phishing report becomes a full incident investigation
  • Not versioning the playbook or scheduling regular review cycles

Output Format

INCIDENT RESPONSE PLAYBOOK
============================
Playbook Name:    Phishing Incident Response
Version:          2.1
Owner:            SOC Manager
Last Reviewed:    2025-11-01
Next Review:      2026-02-01
Trigger:          Phishing email reported via abuse@corp.com or phish button

RACI MATRIX
Activity                    | SOC L1 | SOC L2 | IR Lead | Legal | Comms
Initial Triage              |   R    |   C    |   I     |       |
Email Analysis              |   R    |   A    |   I     |       |
Containment                 |        |   R    |   A     |   I   |
Credential Reset            |        |   R    |   A     |       |
User Notification           |        |   C    |   A     |       |   R
Regulatory Notification     |        |        |   C     |   R   |   A
Lessons Learned             |   C    |   C    |   R     |   I   |   I

PROCEDURE STEPS
[Detailed steps with tool-specific instructions]

DECISION TREE
[Flowchart logic]

ESCALATION MATRIX
[Conditions and contacts]

METRICS
Target MTTA: 15 minutes
Target MTTC: 1 hour
Target MTTR: 4 hours

© mukul975, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 3 other files (scripts, references) in skills/building-incident-response-playbook of mukul975/Anthropic-Cybersecurity-Skills.

  • SKILL.md
  • LICENSE
  • references/api-reference.md
  • scripts/agent.py

Open the folder on GitHubat commit 54a7988

Compare with similar skills

Building Incident Response Playbook next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Building Incident Response Playbook compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Building Incident Response Playbook this skillmukul975/Anthropic-Cybersecurity-Skills34k—~2.6kAutomated safety check: PassApache-2.0
Oncallpigweed-project/pigweed548—~963Automated safety check: PassApache-2.0
Activation Governance Chaos RolloutAli-Marandi/DataSense107—~1.9kAutomated safety check: PassMIT
Incident Response686f6c61/alfred-dev117—~1.1kAutomated safety check: PassMIT
Superset Incident Triagesuperset-sh/superset15k—~1kAutomated safety check: PassCustom licence
Post-Incident DebriefVeryGoodOpenSource/vgv-wingspan109—~1.9kAutomated safety check: PassMIT

Similar skills

  • Oncall

    pigweed-project/pigweed

    Pigweed oncall rotation runbooks and maintenance workflows (such as rolling CIPD client tools for b/315378787).

    548 GitHub stars~963 tokensUpdated today
    DevOps & CloudAuto-check passed
  • Design, validate, and govern fail-closed customer-activation automations that use an Outbox/worker pattern.

    107 GitHub stars~1.9k tokensUpdated 1 mo ago
    DevOps & CloudAuto-check passed
  • Incident Response

    686f6c61/alfred-dev

    Protocolo de respuesta ante incidentes en produccion: triaje, mitigacion, causa raiz y postmortem.

    117 GitHub stars~1.1k tokensUpdated 1 mo ago
    DevOps & CloudAuto-check passed
  • Superset Incident Triage

    superset-sh/superset

    Does a read-only first pass on a possible production incident: gathers deploy, Sentry and health-check signals, proposes a severity and status message, then stops for human approval.

    15k GitHub stars~1k tokensUpdated today
    DevOps & CloudAuto-check passed
  • Post-Incident Debrief

    VeryGoodOpenSource/vgv-wingspan

    Produces a blameless post-incident debrief with timeline, root cause and follow-up actions after an outage, failed release or significant bug, while details are fresh.

    109 GitHub stars~1.9k tokensUpdated 4 days ago
    DevOps & CloudAuto-check passed
  • SRE Engineer

    Jeffallan/claude-skills

    Defines SLIs, SLOs and error budgets, and sets up golden-signal monitoring, blameless postmortems, toil automation and chaos experiments for production systems.

    12k GitHub stars~1.7k tokensUpdated 8 days ago
    DevOps & CloudAuto-check passed

More from mukul975/Anthropic-Cybersecurity-Skills

All 644 skills in this repo
  • Campaign Attribution Evidence Analysis

    mukul975/Anthropic-Cybersecurity-Skills

    Weighs infrastructure, TTP, malware code and timing evidence with the Diamond Model and competing hypotheses to reach a confidence-rated attribution.

    34k GitHub stars~2.3k tokensUpdated 1 mo ago
    Auto-check passed
  • Go Malware Analysis in Ghidra

    mukul975/Anthropic-Cybersecurity-Skills

    Walks through reverse engineering Go-compiled malware in Ghidra: parsing buildinfo and pclntab, recovering stripped function names and extracting dependencies.

    34k GitHub stars~2.8k tokensUpdated 1 mo ago
    Auto-check passed
  • LNK and Jump List Forensics

    mukul975/Anthropic-Cybersecurity-Skills

    Guides forensic analysis of Windows LNK shortcut files and Jump Lists with LECmd, JLECmd and manual parsing to show file access and program execution.

    34k GitHub stars~2.8k tokensUpdated 1 mo ago
    Auto-check passed
  • Malware Persistence Analysis with Autoruns

    mukul975/Anthropic-Cybersecurity-Skills

    Hunts Windows malware persistence with Sysinternals Autoruns, covering run keys, services, scheduled tasks and drivers, with baseline comparison.

    34k GitHub stars~1.2k tokensUpdated 1 mo ago
    Auto-check passed
  • NTFS MFT Deleted File Recovery

    mukul975/Anthropic-Cybersecurity-Skills

    Guides a Windows forensic examination of the NTFS Master File Table to recover deleted-file evidence, build timelines and spot timestomping.

    34k GitHub stars~2.7k tokensUpdated 1 mo ago
    Auto-check passed
  • Network Covert Channel Analysis

    mukul975/Anthropic-Cybersecurity-Skills

    Detects DNS tunneling, ICMP exfiltration and HTTP-based covert channels in packet captures and DNS logs when hunting for hidden command-and-control traffic.

    34k GitHub stars~2k tokensUpdated 1 mo ago
    Auto-check passed

Categories

Questions about Building Incident Response Playbook

What does Building Incident Response Playbook do?

Designs and documents structured incident response playbooks with step-by-step procedures per incident type, decision trees, escalation criteria, RACI matrices, and SOAR platform integration…. Building Incident Response Playbook is an agent skill from mukul975/Anthropic-Cybersecurity-Skills. Designs and documents structured incident response playbooks with step-by-step procedures per incident type, decision trees, escalation criteria, RACI matrices, and SOAR platform integration, aligned to NIST SP 800-61r3 and SANS PICERL.

When should I use Building Incident Response Playbook?

Building Incident Response Playbook fits situations like: maturing an IR program; documenting response runbooks for a new incident type; designing SOAR playbooks.

How do I install Building Incident Response Playbook in Claude Code?

Run `npx skills add mukul975/Anthropic-Cybersecurity-Skills --skill building-incident-response-playbook -a claude-code`. Or copy the skill folder (skills/building-incident-response-playbook in mukul975/Anthropic-Cybersecurity-Skills) into .claude/skills/building-incident-response-playbook in your project. Claude Code loads it when a task matches its description.

How do I install Building Incident Response Playbook in Codex?

Run `npx skills add mukul975/Anthropic-Cybersecurity-Skills --skill building-incident-response-playbook -a codex`. Or copy the skill folder (skills/building-incident-response-playbook in mukul975/Anthropic-Cybersecurity-Skills) into .agents/skills/building-incident-response-playbook in your project. Codex loads it when a task matches its description.

Can I use Building Incident Response Playbook in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add mukul975/Anthropic-Cybersecurity-Skills --skill building-incident-response-playbook -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/building-incident-response-playbook, .gemini/skills/building-incident-response-playbook, .github/skills/building-incident-response-playbook and .opencode/skills/building-incident-response-playbook in your project.

What does Building Incident Response Playbook need to run?

Going by SKILL.md and its folder, Building Incident Response Playbook needs Python for the scripts in its folder. Our summary lists: Python 3.

Does Building Incident Response Playbook access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Building Incident Response Playbook safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.

What licence does Building Incident Response Playbook use?

Building Incident Response Playbook is published under the Apache-2.0 licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Building Incident Response Playbook use?

About 2.6k tokens (SKILL.md is roughly 10k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 592 tokens, read only when the agent opens those files.

What are the alternatives to Building Incident Response Playbook?

Skills that share tags, products or a category with Building Incident Response Playbook: Oncall (pigweed-project/pigweed, 548 stars), Activation Governance Chaos Rollout (Ali-Marandi/DataSense, 107 stars), Incident Response (686f6c61/alfred-dev, 117 stars) and Superset Incident Triage (superset-sh/superset, 15k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Building Incident Response Playbook?

mukul975 (a GitHub user) maintains it in mukul975/Anthropic-Cybersecurity-Skills, which has 34,116 GitHub stars. The repository holds 644 skills in this directory. The repository was last updated on August 31, 2026.

Source: mukul975/Anthropic-Cybersecurity-Skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.