respond-ransomware

Community

Lead ransomware response with PICERL workflow.

Authordandye
Version1.0.0
Installs0

System Documentation

What problem does it solve?

Ransomware incidents require a structured, end-to-end response that coordinates detection, containment, eradication, and recovery across multiple tools and teams. This skill provides a PICERL-based playbook to guide analysts through rapid containment and thorough remediation, minimizing downtime and data loss.

Core Features & Use Cases

  • Orchestrated lifecycle: identification, containment, eradication, and recovery following PICERL.
  • Interlocks with SIEM/SOAR/GTI data and supports case documentation for audit trails.
  • Use Case: When ransomware is detected, trigger containment actions, isolate affected hosts, and document eradication steps to restore operations.

Quick Start

Initiate the ransomware response workflow by supplying CASE_ID and INITIAL_INDICATORS to trigger identification, containment, eradication, and recovery steps.

Dependency Matrix

Required Modules

None required

Components

Standard package

💻 Claude Code Installation

Recommended: Let Claude install automatically. Simply copy and paste the text below to Claude Code.

Please help me install this Skill:
Name: respond-ransomware
Download link: https://github.com/dandye/ai-runbooks/archive/main.zip#respond-ransomware

Please download this .zip file, extract it, and install it in the .claude/skills/ directory.
View Source Repository

Agent Skills Search Helper

Install a tiny helper to your Agent, search and equip skill from 223,000+ vetted skills library on demand.