ir-playbooklisted
Install: claude install-skill noctua84/nescio-ai
# IR Playbook
## Purpose
Create an incident response playbook that delivers actionable, measurable results.
**Category**: Cybersecurity & Information Security
## Inputs
### Required
- **Objective**: What you want to achieve with this deliverable
- **Context**: Relevant background information (systems, scope, environment)
### Optional
- **Constraints**: Any limitations or requirements to consider
- **Existing Work**: Previous documents or data to build on
## Context
Before starting, read the repo's `CLAUDE.md` and any relevant notes under `memory/` (e.g. `memory/repo/<repo>/`, `memory/feedback/`) for prior decisions and constraints.
## Process
### Step 1: Context & Research
- Review any existing incident response playbook documents in the project
- Identify key stakeholders and their requirements
- Select the most appropriate framework: NIST SP 800-61 Rev 2, MITRE ATT&CK (Defensive), SANS PICERL
### Step 2: Analysis & Framework Application
- Apply the selected framework to structure the incident response playbook
- Identify gaps, opportunities, and risks
- Define success metrics: MTTR per Scenario Type, Containment Time, Evidence Collection Completeness, Playbook Execution Success Rate
- Document assumptions and dependencies
- Validate approach against industry best practices
### Step 3: Build the Deliverable
- Structure the incident response playbook using the output format below
- Include specific, actionable recommendations — not generic advice
- Add concrete nu