What problem does it solve? Responding to a security incident under pressure with incomplete information leads to costly mistakes like destroying forensic evidence, missing regulatory notification deadlines, or failing to fully eradicate attacker persistence. This Skill provides structured decision frameworks, playbooks, and checklists so incident handlers make the right call at each stage of the response lifecycle. ## Core Features & Use Cases - Full IR Lifecycle Guidance: Covers the ECIH 9-stage IH&R lifecycle mapped to NIST 800-61 and SANS PICERL, from preparation through post-incident lessons learned. - Incident-Type Playbooks: Step-by-step response guides for ransomware, data breach, account compromise, phishing/BEC, insider threat, DDoS, cloud incidents, and web application compromise. - Forensics & Compliance Support: Order of volatility, chain of custody procedures, evidence documentation templates, and regulatory notification timelines (GDPR 72-hour, HIPAA, PCI DSS). - Use Case: During a ransomware outbreak, use the ransomware playbook to isolate endpoints, capture memory before shutdown, document the ransom note as evidence, and follow the recovery sequence to restore from verified clean backups. ## Quick Start Ask the agent to walk you through containing and collecting evidence for a confirmed ransomware incident on an endpoint.