it-security-response

Triages and coordinates cybersecurity incident response across identity, endpoint, email, cloud, and data domains.

Updated Jun 21, 2026
One-click install
npx skills add https://github.com/lwokeray/cowork-plugins --skill it-security-response-lwokeray
Or copy as Structured Prompt for Agent▼
Please help me install this Agent Skill.
Skill: it-security-response
Source: https://github.com/lwokeray/cowork-plugins/tree/main/plugins/it-operations-cowork/skills/it-security-response
Command: npx skills add https://github.com/lwokeray/cowork-plugins --skill it-security-response-lwokeray

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve? Security teams facing phishing, compromised accounts, malware, or data exposure need a disciplined workflow that preserves evidence, scopes incidents accurately, and applies proportional containment without overreacting or tipping off attackers. ## Core Features & Use Cases - Evidence-First Triage: Records alert sources, preserves logs and artifacts, and separates observed evidence from hypotheses before declaring an incident. - Scoped Containment: Applies the narrowest effective action across identity, endpoint, email, cloud, network, and data domains with documented approval and reversal conditions. - Eradication and Recovery: Removes persistence, rotates compromised credentials with dependency-aware overlap, and validates clean state through monitoring. - Use Case: When a user reports a suspicious sign-in from an impossible travel location, use this Skill to build a cross-domain timeline, revoke sessions, reset authentication methods, and produce a restricted incident record. ## Quick Start Investigate this phishing alert, assess the affected accounts and devices, and draft a containment and recovery plan with an incident record.

Frequently Asked Questions about it-security-response

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I respond to a compromised user account in Microsoft 365?▼

Disable sign-in, revoke active sessions, and reset authentication methods, then investigate mailbox rules, application consents, and data access. Build a timeline across sign-in logs and audit events before declaring full scope, and verify recovery through monitoring.

How do I investigate a phishing email reported by a user?▼

Preserve the message with headers and URLs, then check whether the user clicked links or entered credentials. Review sign-in activity, sessions, forwarding rules, and other recipients of the same message before purging confirmed malicious content.

What containment actions can be taken during a security incident?▼

Containment options include disabling sign-in, isolating devices, purging malicious emails, disabling service principals, blocking network indicators, and suspending data sharing. Apply the narrowest effective action with documented approval, expected impact, and reversal conditions.

Can this Skill handle incidents without access to security logs?▼

Yes, it works with user-provided or authorized exported data when live tools are unavailable. It records collection gaps and retention limits, uses alternate evidence sources, and avoids definitive conclusions that the available evidence cannot support.

When should an alert not be treated as a confirmed incident?▼

An alert without corroborating evidence stays classified as needs investigation rather than an incident. The workflow separates observed evidence from detector hypotheses and analyst inference, and never attributes attackers or breaches without proof.