From dfir
Drive a security incident through the response lifecycle (NIST SP 800-61 / SANS PICERL): triage and scope, contain, eradicate, recover, and capture lessons learned. Use to coordinate or work an active incident. Authorized responders only.
How this skill is triggered — by the user, by Claude, or both
Slash command
/dfir:incident-responseThe summary Claude sees in its skill listing — used to decide when to auto-load this skill
A controlled response that limits damage, removes the adversary, restores
A controlled response that limits damage, removes the adversary, restores operations, and produces an evidence-backed record — without destroying evidence or tipping off the attacker prematurely.
forensic-triage).ioc-development) and feed containment/detection in parallel.An incident record: classification · scope · timeline · actions · IOCs · root cause
· recovery status · lessons. Use security-reporting for the incident report;
recommend detections via detection-engineering.
Contain without destroying evidence or alerting the adversary prematurely — sequence matters. "Eradicated" means the root cause and all persistence are gone, not just the malware you first saw. Capture lessons into durable detections and control changes, or the next incident repeats.
Provides behavioral guidelines to reduce common LLM coding mistakes, focusing on simplicity, surgical changes, assumption surfacing, and verifiable success criteria.
Searches, retrieves, and installs Agent Skills from prompts.chat registry using MCP tools like search_skills and get_skill. Activates for finding skills, browsing catalogs, or extending Claude.
npx claudepluginhub jassics/awesome-claude-security --plugin dfir