跳到主要内容
知仓学习社ZHICANG

incident-response

Runs a security incident from detection to closure — triage, containment, investigation, communication, and the review afterward. Use this when a co…

不碰外部(只输出文字)无严重或高危命中cbrock84/headcount

它会碰到什么

扫了多少2 个文本文件,5 KB
它会碰到什么不碰外部(只输出文字)
命中总数0 处
命中统计严重 0 · 高 0 · 中 0 · 低 0

这一栏是扫描器报的事实,不是结论。命中多不等于有毒(安全工具、规则库、示例脚本本来就会包含危险写法),命中少也不等于干净。它和你手上的凭据、文件、网络有什么关系,需要你自己看。

技能内容

Incident response

> Breach notification runs on statutory clocks, measured in hours in several regimes. Involve Legal

> & Risk and qualified counsel as soon as personal data may be involved — not after the technical

> work is done.

Decide it is an incident, and say so

The most expensive delay is the hour spent debating whether this is really an incident. Declare

early; standing down a declared incident is cheap, and discovering an hour late that it was real is

not.

Name an incident commander immediately. One person, coordinating, not doing the technical work.

Everyone else has a defined job. Incidents fail on coordination far more than on technical

capability.

Order of operations

1. Contain before investigating. Stop the bleeding: isolate the host, revoke the credential,

disable the account, block the path. It is tempting to watch the attacker to learn more — do that

only with a deliberate decision, not by default.

2. Preserve evidence while containing. Snapshot before you rebuild. Capture volatile state —

memory, connections, running processes — before powering anything off. Rebuilding a compromised host

destroys the only record of how they got in, and you will need it.

3. Establish scope. What was accessed, what was taken, when it started, and whether it is still

happening. Assume the initial scope is understated; it usually is. Look for persistence and lateral

movement before declaring containment.

4. Eradicate and recover. Remove the access, close the path, then restore. Rebuild from known

good rather than cleaning in place — you cannot prove a cleaned host is clean.

Rotate every credential the attacker could have reached, not only the ones you know they used.

5. Watch after recovery. Re-entry is common. Monitor specifically for the path they used and its

neighbors.

Communication

Keep one timeline as the single source of truth, updated as facts are established, with each entry

timestamped and attributed. Incidents generate contradictory information at speed, and the timeline

is what stops the same question being answered three ways.

Say what is known, what is not yet known, and when the next update comes. Never speculate on cause

or scope externally before it is established — a retracted statement extends the story and damages

credibility more than the incident did.

Afterward

Blameless review, focused on the system rather than the person. The useful questions: how could this

have been detected sooner, what made containment slow, what did we not have that we needed, and what

made this possible in the first place.

Output actions with owners and dates. A review producing no committed changes is theater, and the

same incident recurs.

Preparation

The plan matters less than having run it. Exercise once a year at minimum: a tabletop against a

realistic scenario finds the gaps — who has authority out of hours, where the credentials are, who

calls counsel — at a time when finding them is free.

Sources

references/sources.md in this skill lists the outside authorities that settle the questions

here — what each one is authoritative for, and what you may do with it. Check them before

answering on anything they cover, and cite what you used. Most are free to read and not free

to reproduce; the use note on each is binding.

Never

  • Rebuild or wipe a compromised host before evidence is captured.
  • Let the person running the technical response also own external communication.
  • Close an incident before you can say how entry happened and that the path is shut.
  • Speculate about cause or attribution outside the response channel while the incident is open.

想直接用这个技能?

本站把开放许可(MIT / Apache 等)的技能按仓库打包整理到网盘,点一下转存到你自己的网盘,不用一个个从 GitHub 拉。许可未声明的技能只给原始仓库链接,不打包。