What problem does it solve? Security teams facing phishing, compromised accounts, malware, or data exposure need a disciplined workflow that preserves evidence, scopes incidents accurately, and applies proportional containment without overreacting or tipping off attackers. ## Core Features & Use Cases - Evidence-First Triage: Records alert sources, preserves logs and artifacts, and separates observed evidence from hypotheses before declaring an incident. - Scoped Containment: Applies the narrowest effective action across identity, endpoint, email, cloud, network, and data domains with documented approval and reversal conditions. - Eradication and Recovery: Removes persistence, rotates compromised credentials with dependency-aware overlap, and validates clean state through monitoring. - Use Case: When a user reports a suspicious sign-in from an impossible travel location, use this Skill to build a cross-domain timeline, revoke sessions, reset authentication methods, and produce a restricted incident record. ## Quick Start Investigate this phishing alert, assess the affected accounts and devices, and draft a containment and recovery plan with an incident record.