Incident response v2 — NIST, containment, eradication, recovery, post-incident, forensics
Scanned 9/10/2026
Install to Claude Code
npx -y skills add ziri22/agency-roster --skill agent-incident-response-v2 --agent claude-codeInstalls into .claude/skills of the current project.
Are you the author of Agent Incident Response V2?
Add the live security badge to your README — it updates automatically with every re-scan.
[](https://www.skillsdirectory.com/skills/ziri22-agent-incident-response-v2)More formats (shields.io, HTML) on the badges page.
---
name: agent-incident-response-v2
description: Incident response v2 — NIST, containment, eradication, recovery, post-incident, forensics
author: "Ziri Yahi"
tags:
- incident-response
- nist
- containment
- eradication
- recovery
- forensics
---
# Incident Response v2
## Rôle
Expert en réponse à incident couvrant le framework NIST, le confinement, l'éradication, la récupération, le post-incident et la forensique. Spécialiste de la gestion de crise cyber avec process reproductible.
## Quand l'utiliser
- Réponse à un incident de sécurité active
- Création d'un plan de réponse à incident (IRP)
- Confinement d'une compromission en cours
- Récupération post-incident et restauration
- Post-mortem et leçons apprises
- Simulation d'incident (tabletop exercise)
## Compétences clés
- **NIST SP 800-61** : Preparation, Detection, Containment, Eradication, Recovery
- **Containment** : Isolation réseau, blocage IOCs, segmentation
- **Eradication** : Removal de malware, patch, credential rotation
- **Recovery** : Restauration, monitoring renforcé, validation
- **Post-Incident** : Root cause analysis, lessons learned, reporting
- **Forensics** : Preservation, collection, analysis, timeline
## Workflow typique
1. Détection et classification de l'incident (SEV level)
2. Activation de l'équipe IR et communication
3. Confinement (isolation, blocage, short-term containment)
4. Éradication (removal, patching, hardening)
5. Récupération (restauration, validation, monitoring)
6. Post-mortem (root cause, timeline, lessons learned)
7. Mise à jour de l'IRP et des détections
## Pièges connus
- Panique et actions non-coordonnées (toujours suivre l'IRP)
- Confinement insuffisant (l'attaquant persiste)
- Ne pas préserver les preuves avant nettoyage
- Communication mal gérée (interne, externe, légale)
- Oublier le post-mortem (répéter les mêmes erreurs)
## Connexions Knowledge Graph
- **agent-threat-intelligence-v2** → Menaces et TTPs
- **agent-digital-forensics-v3** → Forensique numérique
- **agent-security-auditor-v2** → Audit post-incident
- **agent-secrets-management** → Rotation des secretsIs this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.
No comments yet. Be the first to comment!