respond-ransomware
CommunityLead ransomware response with PICERL workflow.
Authordandye
Version1.0.0
Installs0
System Documentation
What problem does it solve?
Ransomware incidents require a structured, end-to-end response that coordinates detection, containment, eradication, and recovery across multiple tools and teams. This skill provides a PICERL-based playbook to guide analysts through rapid containment and thorough remediation, minimizing downtime and data loss.
Core Features & Use Cases
- Orchestrated lifecycle: identification, containment, eradication, and recovery following PICERL.
- Interlocks with SIEM/SOAR/GTI data and supports case documentation for audit trails.
- Use Case: When ransomware is detected, trigger containment actions, isolate affected hosts, and document eradication steps to restore operations.
Quick Start
Initiate the ransomware response workflow by supplying CASE_ID and INITIAL_INDICATORS to trigger identification, containment, eradication, and recovery steps.
Dependency Matrix
Required Modules
None requiredComponents
Standard package💻 Claude Code Installation
Recommended: Let Claude install automatically. Simply copy and paste the text below to Claude Code.
Please help me install this Skill: Name: respond-ransomware Download link: https://github.com/dandye/ai-runbooks/archive/main.zip#respond-ransomware Please download this .zip file, extract it, and install it in the .claude/skills/ directory.
Agent Skills Search Helper
Install a tiny helper to your Agent, search and equip skill from 223,000+ vetted skills library on demand.