containing-active-breach

Featured

Executes containment strategies to stop active adversary operations and prevent lateral movement during a confirmed security breach. Implements short-term and long-term containment using network segmentation, endpoint isolation, credential revocation, and access control modifications. Activates for requests involving breach containment, lateral movement prevention, network isolation, active threat containment, or live incident response.

AI & Automation 12,642 stars 1468 forks Updated today Apache-2.0

Install

View on GitHub

Quality Score: 99/100

Stars 20%
100
Recency 20%
100
Frontmatter 20%
70
Documentation 15%
100
Issue Health 10%
50
License 10%
100
Description 5%
100

Skill Content

# Containing Active Breaches ## When to Use - A confirmed intrusion is in progress with an active adversary on the network - Malware is spreading laterally across endpoints or servers - A compromised account is being used for unauthorized access to systems - Ransomware encryption has been detected and is actively propagating - An attacker has established command-and-control communications from internal hosts **Do not use** for post-incident cleanup when the adversary is no longer active; use eradication procedures instead. ## Prerequisites - Confirmed incident classification with P1 or P2 severity from triage - EDR console access with host isolation capabilities (CrowdStrike Falcon, Microsoft Defender for Endpoint, SentinelOne) - Network firewall and switch management access for segmentation - Active Directory or identity provider administrative access for credential actions - Pre-approved containment authority documented in the incident response plan - Evidence preservation plan to avoid destroying forensic artifacts during containment ## Workflow ### Step 1: Assess Containment Scope Before taking containment actions, map the full scope of compromise to avoid partial containment that alerts the adversary: - Identify all confirmed compromised hosts via EDR telemetry and SIEM correlation - Map lateral movement paths using authentication logs (Windows Event ID 4624 Type 3 and Type 10) - Identify all compromised credentials (check for pass-the-hash, Kerberoasting, DCSyn...

Details

Author
mukul975
Repository
mukul975/Anthropic-Cybersecurity-Skills
Created
3 months ago
Last Updated
today
Language
Python
License
Apache-2.0

Similar Skills

Semantically similar based on skill content — not just same category

DevOps & Infrastructure Featured

performing-cloud-incident-containment-procedures

Execute cloud-native incident containment across AWS, Azure, and GCP by isolating compromised resources, revoking credentials, preserving forensic evidence, and applying security group restrictions to prevent lateral movement.

12,642 Updated today
mukul975
AI & Automation Featured

conducting-malware-incident-response

Responds to malware infections across enterprise endpoints by identifying the malware family, determining infection vectors, assessing spread, and executing eradication procedures. Covers the full lifecycle from detection through containment, analysis, removal, and recovery. Activates for requests involving malware response, malware eradication, trojan removal, worm containment, malware triage, or infected endpoint remediation.

12,642 Updated today
mukul975
DevOps & Infrastructure Featured

conducting-cloud-incident-response

Responds to security incidents in cloud environments (AWS, Azure, GCP) by performing identity-based containment, cloud-native log analysis, resource isolation, and forensic evidence acquisition adapted for ephemeral cloud infrastructure. Activates for requests involving cloud incident response, AWS security incident, Azure compromise, GCP breach, cloud forensics, or cloud identity compromise.

12,642 Updated today
mukul975
AI & Automation Featured

hunting-for-supply-chain-compromise

Hunt for supply chain compromise indicators including trojanized software updates, compromised dependencies, unauthorized code modifications, and tampered build artifacts.

12,642 Updated today
mukul975
AI & Automation Featured

implementing-continuous-security-validation-with-bas

Deploy Breach and Attack Simulation tools to continuously validate security control effectiveness by safely emulating real-world attack techniques across the kill chain.

12,642 Updated today
mukul975