Recover from an incident by eradicating compromise and restoring service. Use when hosts, identities, applications, cloud resources, network controls, or data need rebuild, patching, rotation, repair, validation, and return to service.
Scanned 9/5/2026
Install to Claude Code
npx -y skills add gaelic-ghost/socket --skill recover-security-incident --agent claude-codeInstalls into .claude/skills of the current project.
Are you the author of Recover Security Incident?
Add the live security badge to your README — it updates automatically with every re-scan.
[](https://www.skillsdirectory.com/skills/gaelic-ghost-recover-security-incident-socket)More formats (shields.io, HTML) on the badges page.
---
name: recover-security-incident
description: Recover from an incident by eradicating compromise and restoring service. Use when hosts, identities, applications, cloud resources, network controls, or data need rebuild, patching, rotation, repair, validation, and return to service.
---
# Recover Security Incident
## Overview
Return systems and people to a trusted operating state using explicit eradication and validation criteria. Recovery is complete only when restored behavior, security controls, access, monitoring, and residual risk are verified.
Read [references/recovery-gates.md](references/recovery-gates.md) for staged return-to-service gates.
## Workflow
1. Establish eradication criteria.
- Identify root/access path, persistence, affected identities/secrets, vulnerable configuration/code, related artifacts, and known scope.
2. Choose restore basis.
- Decide clean rebuild, known-good backup, patched image, repaired configuration, provider recovery, or controlled cleanup from evidence and integrity confidence.
3. Eradicate.
- Remove verified mechanisms, patch or mitigate the entry path, rotate/revoke secrets and sessions from trusted systems, repair policies/configuration, and preserve evidence of changes.
4. Restore in stages.
- Validate offline or isolated, restore dependencies/data, enable limited traffic/users, monitor, then broaden service.
5. Verify security and function.
- Reproduce the original detection/path as a negative test, confirm expected functionality, review access/persistence/network/logging, and check backups and monitoring.
6. Remove temporary controls deliberately.
- Inventory emergency rules, disabled services, isolation, temporary accounts, logging, tokens, and exceptions; retain only approved controls with owners/expiry.
7. Close and improve.
- Record timeline, root cause, affected scope, actions, notifications, evidence retention, lessons, structural hardening, and residual risk owner.
## Output
Return eradication evidence, restore basis, staged recovery results, negative retest, temporary-control disposition, monitoring window, lessons/actions, and residual-risk decision.
Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.
No comments yet. Be the first to comment!