Agent skill

Implementing Ot Incident Response Playbook

by mukul975 in mukul975/Anthropic-Cybersecurity-Skills

Develops OT-specific incident response playbooks using a SANS PICERL-based Python engine that classifies incident severity (safety, process, access, recon) and coordinates IT SOC, OT engineering…

Apache-2.0Auto-check passedDevOps & Cloud

Install Implementing Ot Incident Response Playbook

skills CLI
$ npx skills add mukul975/Anthropic-Cybersecurity-Skills --skill implementing-ot-incident-response-playbook -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install mukul975/Anthropic-Cybersecurity-Skills implementing-ot-incident-response-playbook --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/mukul975/Anthropic-Cybersecurity-Skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/implementing-ot-incident-response-playbook .claude/skills/implementing-ot-incident-response-playbook && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
implementing-ot-incident-response-playbook
GitHub stars
34k
Token cost
~4.2k tokens
SKILL.md length
428 words
Files
4 (incl. scripts, references)
Skills in repo
644
Repo updated
First seen
Licence
Apache-2.0

At a glance

Develops OT-specific incident response playbooks using a SANS PICERL-based Python engine that classifies incident severity (safety, process, access, recon) and coordinates IT SOC, OT engineering…

  • Works in 8 steps: Activate the OT IR playbook for… → Sever IT-OT connectivity at the DMZ… → Verify PLCs are still running and… → …
  • Building ICS/SCADA incident response procedures for the first time
  • SKILL.md covers When to Use, Prerequisites, Workflow and Key Concepts, plus 2 more sections
  • Runs Python scripts from its folder

What it does

Implementing Ot Incident Response Playbook is an agent skill from mukul975/Anthropic-Cybersecurity-Skills. Develops OT-specific incident response playbooks using a SANS PICERL-based Python engine that classifies incident severity (safety, process, access, recon) and coordinates IT SOC, OT engineering, and plant operations, aligned with IEC 62443 and NIST SP 800-82. Use when building ICS/SCADA incident response procedures for the first time, preparing for OT ransomware scenarios, or aligning IR with IEC 62443/NERC CIP reporting requirements.

Its SKILL.md is about 4.2k tokens, which your agent loads only when the skill is triggered. The skill folder holds 5 other files, including scripts and reference files (for example `references/api-reference.md` and `scripts/agent.py`).

It sits in DevOps & Cloud, covering Incident response. It works with Python. The repository describes itself as: 817 structured cybersecurity skills for AI agents · Mapped to 6 frameworks: MITRE ATT&CK, NIST CSF 2.0, MITRE ATLAS, D3FEND, NIST AI RMF & MITRE F3 (Fight Fraud) · agentskills.io…. The licence is Apache-2.0.

When your agent uses it

  • Building ICS/SCADA incident response procedures for the first time
  • Preparing for OT ransomware scenarios
  • Aligning IR with IEC 62443/NERC CIP reporting requirements

Example prompts

  • “Use the implementing-ot-incident-response-playbook skill to develop OT-specific incident response playbooks using a SANS PICERL-based Python engine…”
  • “/implementing-ot-incident-response-playbook”

Requirements

  • Python 3

Workflow steps

8 steps, taken from the first numbered list in SKILL.md.

  1. Activate the OT IR playbook for ransomware immediately
  2. Sever IT-OT connectivity at the DMZ firewall (both north and south firewalls)
  3. Verify PLCs are still running and process is stable (PLCs run independently of IT)
  4. Switch operators to local HMI panels if networked HMIs are affected
  5. Assess which Level 2/3 systems are encrypted vs operational
  6. Prioritize restoring HMI visibility, then historian, then engineering workstations
  7. Restore from offline backups -- never attempt to decrypt using attacker-provided tools without sandbox testing
  8. Report to CISA within 72 hours per CIRCIA requirements

What it can do on your machine

Read from SKILL.md and the folder at commit 54a7988. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Ships 1 file in scripts/ (Python), which the agent can run.

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Implementing Ot Incident Response Playbook loads about 4.2k tokens when it runs, and up to ~4.9k if it reads all its reference files. Until then it costs about 121 tokens; SKILL.md has 428 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~121
When it runs · the whole SKILL.md, loaded when a task matches
~4.2k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~4.9k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.

SKILL.md

The full file from mukul975/Anthropic-Cybersecurity-Skills at commit 54a7988, republished under its Apache-2.0 licence (© mukul975). 428 words, ~4,234 tokens.

Download SKILL.mdSave it as .claude/skills/implementing-ot-incident-response-playbook/SKILL.md (or your agent's skills folder). This skill also uses 3 other files; get the full folder from GitHub.
name
implementing-ot-incident-response-playbook
description
Develops OT-specific incident response playbooks using a SANS PICERL-based Python engine that classifies incident severity (safety, process, access, recon) and coordinates IT SOC, OT engineering, and plant operations, aligned with IEC 62443 and NIST SP 800-82. Use when building ICS/SCADA incident response procedures for the first time, preparing for OT ransomware scenarios, or aligning IR with IEC 62443/NERC CIP reporting requirements.
domain
cybersecurity
subdomain
ot-ics-security
tags
ot-security, ics, incident-response, playbook, sans, iec62443, nist, safety-critical
version
1.0
author
mahipal
license
Apache-2.0
nist_csf
PR.IR-01, DE.CM-01, ID.AM-05, GV.OC-02
mitre_attack
T1078, T1190, T1059, T0816, T0836

Implementing OT Incident Response Playbook

When to Use

  • When building OT-specific incident response procedures for the first time
  • When existing IT IR playbooks do not address ICS/SCADA-specific requirements
  • When preparing for OT ransomware scenarios like EKANS or LockerGoga
  • When aligning IR procedures with IEC 62443 and NERC CIP incident reporting requirements
  • When conducting post-incident reviews to improve OT IR capabilities

Do not use for IT-only incident response without OT components (use standard NIST 800-61 playbooks), for day-to-day OT security monitoring (see implementing-dragos-platform-for-ot-monitoring), or for tabletop exercise design (see performing-ics-tabletop-exercise).

Prerequisites

  • OT asset inventory with criticality ratings and safety system identification
  • Defined roles: OT IR Lead, IT SOC Analyst, Plant Operations Manager, Process Safety Engineer
  • Communication plan including out-of-band channels (OT incidents may compromise IT communications)
  • Known-good backups of PLC programs, HMI configurations, and historian data
  • Contact information for ICS vendors, Dragos/Claroty support, and CISA ICS-CERT

Workflow

Step 1: Define OT-Specific Incident Classification and Response Procedures
python
#!/usr/bin/env python3
"""OT Incident Response Playbook Engine.

Implements structured OT incident response procedures following
SANS PICERL lifecycle with ICS-specific considerations for safety,
availability, and cross-team coordination.
"""

import json
import sys
from datetime import datetime
from enum import Enum
from typing import Dict, List, Optional


class OTIncidentSeverity(Enum):
    SEV1_SAFETY = "SEV1-SAFETY"  # Safety system compromise
    SEV2_PROCESS = "SEV2-PROCESS"  # Active process manipulation
    SEV3_ACCESS = "SEV3-ACCESS"  # Unauthorized OT access
    SEV4_RECON = "SEV4-RECON"  # Reconnaissance in OT network
    SEV5_IT_SPILLOVER = "SEV5-IT-SPILLOVER"  # IT incident with OT exposure


class OTIncidentCategory(Enum):
    RANSOMWARE = "ransomware"
    MALWARE_ICS = "malware_ics_specific"
    UNAUTHORIZED_ACCESS = "unauthorized_ot_access"
    PROCESS_MANIPULATION = "process_manipulation"
    SIS_COMPROMISE = "safety_system_compromise"
    DATA_EXFILTRATION = "ot_data_exfiltration"
    SUPPLY_CHAIN = "supply_chain_compromise"
    INSIDER_THREAT = "insider_threat"


# PICERL phase definitions for OT
PICERL_PHASES = {
    "preparation": {
        "description": "Readiness activities before an incident occurs",
        "ot_specific": [
            "Maintain offline backups of all PLC programs and HMI configurations",
            "Document safe shutdown procedures for each process area",
            "Establish out-of-band communication (satellite phone, analog radio)",
            "Pre-stage forensic tools that work in air-gapped OT networks",
            "Maintain spare PLCs and engineering workstations",
            "Conduct quarterly OT tabletop exercises",
        ],
    },
    "identification": {
        "description": "Detect and confirm the OT security incident",
        "ot_specific": [
            "Correlate OT IDS alerts with process anomalies from historian data",
            "Verify if process deviations are cyber-caused vs operational",
            "Check Safety Instrumented Systems (SIS) status and integrity",
            "Review engineering workstation logs for unauthorized access",
            "Examine PLC mode changes (RUN/STOP/PROGRAM transitions)",
            "Assess whether the incident is IT-only or has crossed into OT",
        ],
    },
    "containment": {
        "description": "Limit the spread and impact of the incident",
        "ot_specific": [
            "NEVER shut down OT systems without plant operations approval",
            "Isolate affected segments at the industrial firewall (not by powering off)",
            "Switch PLCs to LOCAL/MANUAL mode if remote manipulation is suspected",
            "Disconnect IT-OT conduits at the DMZ while maintaining intra-OT communication",
            "Preserve forensic evidence before any remediation actions",
            "Maintain safety system operation throughout containment",
        ],
    },
    "eradication": {
        "description": "Remove the threat from OT systems",
        "ot_specific": [
            "Compare running PLC programs against known-good backups",
            "Rebuild compromised engineering workstations from golden images",
            "Verify historian data integrity for evidence of manipulation",
            "Check for persistence mechanisms in OT-specific locations (startup scripts, scheduled tasks on HMIs)",
            "Validate firmware integrity on PLCs and RTUs",
            "Coordinate with ICS vendor for rootkit-level remediation if needed",
        ],
    },
    "recovery": {
        "description": "Restore OT operations to normal",
        "ot_specific": [
            "Restore PLC programs from verified offline backups",
            "Bring processes back online in stages with engineering oversight",
            "Monitor process variables closely during restart for anomalies",
            "Validate safety system functionality before resuming automatic operation",
            "Re-enable IT-OT connectivity only after OT is verified clean",
            "Document any process variable drift during the incident",
        ],
    },
    "lessons_learned": {
        "description": "Post-incident review and improvement",
        "ot_specific": [
            "Conduct joint IT/OT post-incident review within 2 weeks",
            "Update detection rules based on observed attack techniques",
            "Revise network segmentation if lateral movement was successful",
            "Update PLC backup schedules based on recovery time experienced",
            "Report to CISA ICS-CERT and sector ISAC as required",
            "Test updated playbook within 90 days",
        ],
    },
}


class OTIncident:
    """Represents an active OT security incident."""

    def __init__(self, title: str, severity: OTIncidentSeverity,
                 category: OTIncidentCategory, affected_systems: List[str]):
        self.id = f"OT-IR-{datetime.now().strftime('%Y%m%d-%H%M%S')}"
        self.title = title
        self.severity = severity
        self.category = category
        self.affected_systems = affected_systems
        self.created = datetime.now().isoformat()
        self.current_phase = "identification"
        self.timeline = []
        self.decisions = []
        self.containment_actions = []

    def log_event(self, phase: str, action: str, actor: str, notes: str = ""):
        """Log an incident response action."""
        entry = {
            "timestamp": datetime.now().isoformat(),
            "phase": phase,
            "action": action,
            "actor": actor,
            "notes": notes,
        }
        self.timeline.append(entry)
        return entry

    def log_decision(self, decision: str, rationale: str, approved_by: str):
        """Log a critical decision during incident response."""
        entry = {
            "timestamp": datetime.now().isoformat(),
            "decision": decision,
            "rationale": rationale,
            "approved_by": approved_by,
        }
        self.decisions.append(entry)
        return entry


class OTPlaybookEngine:
    """Executes OT incident response playbooks."""

    def __init__(self):
        self.playbooks = self._build_playbooks()

    def _build_playbooks(self) -> Dict:
        """Build category-specific OT IR playbooks."""
        return {
            OTIncidentCategory.RANSOMWARE: {
                "name": "OT Ransomware Response",
                "reference": "SANS ICS Ransomware Defense Playbook",
                "immediate_actions": [
                    "DO NOT pay ransom without executive and legal approval",
                    "Disconnect IT-OT conduit at DMZ firewalls immediately",
                    "Verify SIS/safety systems are operating independently",
                    "Switch critical processes to manual/local control",
                    "Preserve ransom note and encrypted file samples for forensics",
                    "Assess if ransomware has reached Level 2 or below",
                ],
                "containment_steps": [
                    "Block lateral movement by disabling SMB/RDP between OT hosts",
                    "Isolate affected VLANs while maintaining critical process communication",
                    "Disable remote access VPN to OT environment",
                    "Check if backup infrastructure is intact (ransomware targets backups)",
                    "Inventory which OT systems are encrypted vs still operational",
                ],
                "recovery_priority": [
                    "1. Safety Instrumented Systems (SIS)",
                    "2. Critical process controllers (PLCs in continuous process)",
                    "3. HMIs for operator visibility",
                    "4. Historian for data continuity",
                    "5. Engineering workstations",
                    "6. IT-OT connectivity (last)",
                ],
                "reporting": [
                    "CISA: report within 72 hours per CIRCIA",
                    "Sector ISAC: share IOCs within 24 hours",
                    "NERC (if applicable): report within 1 hour for BES impact",
                ],
            },
            OTIncidentCategory.SIS_COMPROMISE: {
                "name": "Safety System Compromise Response",
                "reference": "TRITON/TRISIS Incident Lessons Learned",
                "immediate_actions": [
                    "IMMEDIATELY alert Process Safety team",
                    "Verify physical safety devices are functional (relief valves, rupture discs)",
                    "Consider controlled process shutdown if SIS integrity is uncertain",
                    "Isolate SIS network from all other networks",
                    "Check if SIS is in bypass mode or has been disarmed",
                    "Engage SIS vendor emergency support (Schneider Triconex, HIMA, etc)",
                ],
                "containment_steps": [
                    "Physically disconnect the SIS engineering workstation from network",
                    "Capture forensic image of SIS engineering workstation",
                    "Verify SIS controller firmware and logic against factory baseline",
                    "Check for unauthorized TriStation/safety protocol connections",
                    "Inspect all engineering workstations for TRITON indicators",
                ],
                "recovery_priority": [
                    "1. Verify all physical safety barriers are intact",
                    "2. Reload SIS logic from offline backup (verified against vendor baseline)",
                    "3. Full SIS proof test before returning to service",
                    "4. Independent verification by process safety engineer",
                ],
                "reporting": [
                    "CISA ICS-CERT: immediate notification for SIS-targeting attack",
                    "Process safety regulator (OSHA, HSE): as required by jurisdiction",
                    "SIS vendor: engage for root cause analysis",
                ],
            },
        }

    def execute_playbook(self, incident: OTIncident):
        """Execute the appropriate playbook for an incident."""
        playbook = self.playbooks.get(incident.category)
        if not playbook:
            print(f"[!] No specific playbook for {incident.category.value}. Using generic OT IR procedures.")
            return

        print(f"\n{'='*70}")
        print(f"OT INCIDENT RESPONSE PLAYBOOK ACTIVATED")
        print(f"{'='*70}")
        print(f"Incident ID: {incident.id}")
        print(f"Title: {incident.title}")
        print(f"Severity: {incident.severity.value}")
        print(f"Category: {incident.category.value}")
        print(f"Playbook: {playbook['name']}")
        print(f"Reference: {playbook['reference']}")
        print(f"Activated: {incident.created}")
        print(f"Affected Systems: {', '.join(incident.affected_systems)}")

        print(f"\n--- IMMEDIATE ACTIONS (Execute within first 15 minutes) ---")
        for i, action in enumerate(playbook["immediate_actions"], 1):
            print(f"  {i}. {action}")

        print(f"\n--- CONTAINMENT STEPS ---")
        for i, step in enumerate(playbook["containment_steps"], 1):
            print(f"  {i}. {step}")

        print(f"\n--- RECOVERY PRIORITY ORDER ---")
        for item in playbook["recovery_priority"]:
            print(f"  {item}")

        print(f"\n--- REPORTING REQUIREMENTS ---")
        for req in playbook["reporting"]:
            print(f"  - {req}")

        # Print PICERL phase guidance
        print(f"\n--- PICERL PHASE CHECKLIST ---")
        for phase, info in PICERL_PHASES.items():
            print(f"\n  [{phase.upper()}] {info['description']}")
            for item in info["ot_specific"][:3]:
                print(f"    - {item}")


if __name__ == "__main__":
    engine = OTPlaybookEngine()

    # Example: OT Ransomware incident
    incident = OTIncident(
        title="Ransomware detected on Level 3 historian servers",
        severity=OTIncidentSeverity.SEV2_PROCESS,
        category=OTIncidentCategory.RANSOMWARE,
        affected_systems=["HIST-01", "HIST-02", "ENG-WS-03", "HMI-AREA1"],
    )

    engine.execute_playbook(incident)

Key Concepts

TermDefinition
PICERLSANS incident response lifecycle: Preparation, Identification, Containment, Eradication, Recovery, Lessons Learned
ICS4ICSIncident Command System for Industrial Control Systems -- adapts FEMA ICS to OT cybersecurity response
Safety Instrumented System (SIS)Independent safety controller that prevents hazardous conditions; compromising SIS can cause physical harm
Manual/Local ModeOperating PLCs with local panel controls instead of remote SCADA; used when remote access is compromised
CIRCIACyber Incident Reporting for Critical Infrastructure Act requiring reporting to CISA within 72 hours
Known-Good BackupVerified, offline copy of PLC programs and configurations used as the trusted baseline for recovery

Common Scenarios

Show full SKILL.md (173 more words)Show less
Scenario: Ransomware Spreads from IT to OT Level 3

Context: Ransomware encrypts enterprise IT systems and spreads through an inadequately protected IT/OT conduit to Level 3 historian servers. HMIs at Level 2 begin showing connectivity errors.

Approach:

  1. Activate the OT IR playbook for ransomware immediately
  2. Sever IT-OT connectivity at the DMZ firewall (both north and south firewalls)
  3. Verify PLCs are still running and process is stable (PLCs run independently of IT)
  4. Switch operators to local HMI panels if networked HMIs are affected
  5. Assess which Level 2/3 systems are encrypted vs operational
  6. Prioritize restoring HMI visibility, then historian, then engineering workstations
  7. Restore from offline backups -- never attempt to decrypt using attacker-provided tools without sandbox testing
  8. Report to CISA within 72 hours per CIRCIA requirements

Pitfalls: Do not shut down PLCs to "protect" them from ransomware -- PLCs run firmware, not Windows, and are typically unaffected by ransomware. Shutting down PLCs disrupts the physical process. Never reconnect IT-OT conduit until the IT side is fully remediated.

Output Format

OT INCIDENT RESPONSE REPORT
==============================
Incident ID: OT-IR-YYYYMMDD-HHMMSS
Severity: SEV[1-5]
Category: [category]
Status: [Active/Contained/Eradicated/Recovered/Closed]

TIMELINE:
  [timestamp] - [phase] - [action] - [actor]

AFFECTED SYSTEMS:
  Safety Systems: [status]
  Process Controllers: [status]
  HMI/SCADA: [status]
  Historian: [status]

DECISIONS LOG:
  [timestamp] - [decision] - [rationale] - [approver]

CONTAINMENT ACTIONS TAKEN:
  1. [action and timestamp]

RECOVERY STATUS:
  [system] - [restored/pending] - [ETA]

© mukul975, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 3 other files (scripts, references) in skills/implementing-ot-incident-response-playbook of mukul975/Anthropic-Cybersecurity-Skills.

  • SKILL.md
  • LICENSE
  • references/api-reference.md
  • scripts/agent.py

Open the folder on GitHubat commit 54a7988

Compare with similar skills

Implementing Ot Incident Response Playbook next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Implementing Ot Incident Response Playbook compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Implementing Ot Incident Response Playbook this skillmukul975/Anthropic-Cybersecurity-Skills34k—~4.2kAutomated safety check: PassApache-2.0
Devops AgentLeoYeAI/openclaw-master-skills2.2k—~5.3kAutomated safety check: NotesMIT
Security Setupluongnv89/skills131—~4.5kAutomated safety check: PassMIT
AWS Cdk Developmentzxkane/aws-skills3672 repos~2.5kAutomated safety check: PassMIT
Reproduce macOS Python FlavorsNuitka/Nuitka15k—~1.7kAutomated safety check: PassAGPL-3.0
Env Var Conventionssgl-project/sglang37k2 repos~2.9kAutomated safety check: PassApache-2.0

Similar skills

  • Devops Agent

    LeoYeAI/openclaw-master-skills

    Your on-call DevOps assistant — one-click deploy, monitoring setup, scheduled backups, and fault diagnosis.

    2.2k GitHub stars~5.3k tokensUpdated 2 mo ago
    DevOps & CloudAuto-check: notes
  • Security Setup

    luongnv89/skills

    Install local-first security hardening: pre-commit secret detection, offline dependency scans, static analysis, reports, and gated free CI.

    131 GitHub stars~4.5k tokensUpdated today
    SecurityAuto-check passed
  • AWS Cdk Development

    zxkane/aws-skills

    AWS Cloud Development Kit (CDK) expert for building cloud infrastructure with TypeScript/Python.

    367 GitHub starsUsed in 2 repos~2.5k tokens
    DevOps & CloudAuto-check passed
  • Reproduce macOS Nuitka issues across Python distributions and GitHub Actions Python packaging.

    15k GitHub stars~1.7k tokensUpdated today
    DevOps & CloudAuto-check passed
  • Env Var Conventions

    sgl-project/sglang

    Conventions for SGLang environment variables — where to define, how to access, how to name, and how to deprecate.

    37k GitHub starsUsed in 2 repos~2.9k tokens
    DevOps & CloudAuto-check passed
  • Pymobiledevice3 Device Operator

    doronz88/pymobiledevice3

    Operate iOS and iPadOS devices with pymobiledevice3, from a local checkout or straight from PyPI via uvx on a fresh workstation.

    2.9k GitHub stars~1.8k tokensUpdated today
    DevOps & CloudAuto-check: notes

More from mukul975/Anthropic-Cybersecurity-Skills

All 644 skills in this repo
  • Campaign Attribution Evidence Analysis

    mukul975/Anthropic-Cybersecurity-Skills

    Weighs infrastructure, TTP, malware code and timing evidence with the Diamond Model and competing hypotheses to reach a confidence-rated attribution.

    34k GitHub stars~2.3k tokensUpdated 1 mo ago
    Auto-check passed
  • Go Malware Analysis in Ghidra

    mukul975/Anthropic-Cybersecurity-Skills

    Walks through reverse engineering Go-compiled malware in Ghidra: parsing buildinfo and pclntab, recovering stripped function names and extracting dependencies.

    34k GitHub stars~2.8k tokensUpdated 1 mo ago
    Auto-check passed
  • LNK and Jump List Forensics

    mukul975/Anthropic-Cybersecurity-Skills

    Guides forensic analysis of Windows LNK shortcut files and Jump Lists with LECmd, JLECmd and manual parsing to show file access and program execution.

    34k GitHub stars~2.8k tokensUpdated 1 mo ago
    Auto-check passed
  • Malware Persistence Analysis with Autoruns

    mukul975/Anthropic-Cybersecurity-Skills

    Hunts Windows malware persistence with Sysinternals Autoruns, covering run keys, services, scheduled tasks and drivers, with baseline comparison.

    34k GitHub stars~1.2k tokensUpdated 1 mo ago
    Auto-check passed
  • NTFS MFT Deleted File Recovery

    mukul975/Anthropic-Cybersecurity-Skills

    Guides a Windows forensic examination of the NTFS Master File Table to recover deleted-file evidence, build timelines and spot timestomping.

    34k GitHub stars~2.7k tokensUpdated 1 mo ago
    Auto-check passed
  • Network Covert Channel Analysis

    mukul975/Anthropic-Cybersecurity-Skills

    Detects DNS tunneling, ICMP exfiltration and HTTP-based covert channels in packet captures and DNS logs when hunting for hidden command-and-control traffic.

    34k GitHub stars~2k tokensUpdated 1 mo ago
    Auto-check passed

Works with

Categories

Questions about Implementing Ot Incident Response Playbook

What does Implementing Ot Incident Response Playbook do?

Develops OT-specific incident response playbooks using a SANS PICERL-based Python engine that classifies incident severity (safety, process, access, recon) and coordinates IT SOC, OT engineering…. Implementing Ot Incident Response Playbook is an agent skill from mukul975/Anthropic-Cybersecurity-Skills. Develops OT-specific incident response playbooks using a SANS PICERL-based Python engine that classifies incident severity (safety, process, access, recon) and coordinates IT SOC, OT engineering, and plant operations, aligned with IEC 62443 and NIST SP 800-82.

When should I use Implementing Ot Incident Response Playbook?

Implementing Ot Incident Response Playbook fits situations like: building ICS/SCADA incident response procedures for the first time; preparing for OT ransomware scenarios; aligning IR with IEC 62443/NERC CIP reporting requirements.

How do I install Implementing Ot Incident Response Playbook in Claude Code?

Run `npx skills add mukul975/Anthropic-Cybersecurity-Skills --skill implementing-ot-incident-response-playbook -a claude-code`. Or copy the skill folder (skills/implementing-ot-incident-response-playbook in mukul975/Anthropic-Cybersecurity-Skills) into .claude/skills/implementing-ot-incident-response-playbook in your project. Claude Code loads it when a task matches its description.

How do I install Implementing Ot Incident Response Playbook in Codex?

Run `npx skills add mukul975/Anthropic-Cybersecurity-Skills --skill implementing-ot-incident-response-playbook -a codex`. Or copy the skill folder (skills/implementing-ot-incident-response-playbook in mukul975/Anthropic-Cybersecurity-Skills) into .agents/skills/implementing-ot-incident-response-playbook in your project. Codex loads it when a task matches its description.

Can I use Implementing Ot Incident Response Playbook in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add mukul975/Anthropic-Cybersecurity-Skills --skill implementing-ot-incident-response-playbook -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/implementing-ot-incident-response-playbook, .gemini/skills/implementing-ot-incident-response-playbook, .github/skills/implementing-ot-incident-response-playbook and .opencode/skills/implementing-ot-incident-response-playbook in your project.

What does Implementing Ot Incident Response Playbook need to run?

Going by SKILL.md and its folder, Implementing Ot Incident Response Playbook needs Python for the scripts in its folder. Our summary lists: Python 3.

Does Implementing Ot Incident Response Playbook access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Implementing Ot Incident Response Playbook safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.

What licence does Implementing Ot Incident Response Playbook use?

Implementing Ot Incident Response Playbook is published under the Apache-2.0 licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Implementing Ot Incident Response Playbook use?

About 4.2k tokens (SKILL.md is roughly 17k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 660 tokens, read only when the agent opens those files.

What are the alternatives to Implementing Ot Incident Response Playbook?

Skills that share tags, products or a category with Implementing Ot Incident Response Playbook: Devops Agent (LeoYeAI/openclaw-master-skills, 2.2k stars), Security Setup (luongnv89/skills, 131 stars), AWS Cdk Development (zxkane/aws-skills, 367 stars) and Reproduce macOS Python Flavors (Nuitka/Nuitka, 15k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Implementing Ot Incident Response Playbook?

mukul975 (a GitHub user) maintains it in mukul975/Anthropic-Cybersecurity-Skills, which has 34,116 GitHub stars. The repository holds 644 skills in this directory. The repository was last updated on August 31, 2026.

Source: mukul975/Anthropic-Cybersecurity-Skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.