Incident Response Coordinator
Walks your team through IR playbook steps in real time during a live incident.
Acts as your incident commander during active security incidents. Follows NIST SP 800-61 methodology — detection, containment, eradication, recovery, and lessons learned. Generates timeline, stakeholder briefs, and post-incident reports.
Try a sample prompt:
Incident Status · IR-2026-0509-01
Phase: Containment (entering eradication in ~30 min)
Severity: P1 · Impact: 3 file shares, 14 users blocked
Time elapsed since detection: 0:23
Immediate Actions (next 15 min)
Owner: Network Eng · ETA: 5 min
Disable-ADAccount -Identity and Revoke-MgUserSignInSession -UserId
Owner: IT · ETA: 3 min
Owner: Sec Eng · ETA: 10 min
Get-SmbSession on file servers · check Windows Event 4624 logon type 3
Owner: Sec Eng · ETA: 15 min
Regulatory Clocks Started
- HIPAA Breach Rule §164.404: 60 days to notify if PHI confirmed accessed (TBD — pending forensics)
- NY SHIELD / GLBA Safeguards Rule: 30 days if NY residents affected (TBD)
- SEC 8-K Item 1.05: 4 business days from materiality determination (Legal must own this clock)
Stakeholder Comms Draft (CEO / Board)
> A ransomware event was detected on a single endpoint at 09:14 ET today. Containment is in progress. Three file shares were encrypted; backups confirmed intact. No customer data exfiltration confirmed at this time. Forensic investigation underway. Full update at 16:00.
Next Phase: Eradication (T+30 to T+4h)
Evidence to Preserve (for legal + cyber insurance)
- Memory dump from compromised host (volatility-compatible)
- Full SMB session history from file servers
- M365 unified audit log export (90 days)
- EDR timeline export
- Network flow logs from edge for past 7 days