Agent Registry·Security·Incident Response Coordinator
Securityclaude-sonnet-4-6Open source · Free to copy

Incident Response Coordinator

Walks your team through IR playbook steps in real time during a live incident.

Acts as your incident commander during active security incidents. Follows NIST SP 800-61 methodology — detection, containment, eradication, recovery, and lessons learned. Generates timeline, stakeholder briefs, and post-incident reports.

Tools:bashweb_searchread
Frameworks:NIST SP 800-61ISO 27035SOC 2HIPAA Breach Rule
Use case 1
Live incident in progress and you need a calm playbook that walks you through containment without forgetting steps
Phase-by-phase action list with owner assignments, regulatory notification clocks ticking visibly, and a clean timeline you can hand to legal at close-out
Use case 2
Tabletop exercise and you need a realistic injection-driven scenario your team has not seen before
NIST SP 800-61-phased scenario with injects calibrated to your stack, discussion prompts at each decision point, and a scoring rubric
Use case 3
Post-incident retrospective and you need to surface what your playbook missed
Gap analysis against your IR plan with specific playbook updates, detection rule recommendations, and control improvements

Try a sample prompt:

incident-response-coordinator · live demo · gemini-flash
◇ Curated sample output (real format)

Incident Status · IR-2026-0509-01

Phase: Containment (entering eradication in ~30 min)

Severity: P1 · Impact: 3 file shares, 14 users blocked

Time elapsed since detection: 0:23

Immediate Actions (next 15 min)

1. Isolate the compromised workstation: disable network at switch (do NOT power off — preserve memory for forensics)

Owner: Network Eng · ETA: 5 min

2. Disable the user's AD account and revoke all M365 active sessions

Disable-ADAccount -Identity and Revoke-MgUserSignInSession -UserId

Owner: IT · ETA: 3 min

3. Snapshot the host disk for forensic chain of custody before any reboot

Owner: Sec Eng · ETA: 10 min

4. Identify lateral movement: pull all SMB sessions from compromised host in last 72h

Get-SmbSession on file servers · check Windows Event 4624 logon type 3

Owner: Sec Eng · ETA: 15 min

Regulatory Clocks Started

- HIPAA Breach Rule §164.404: 60 days to notify if PHI confirmed accessed (TBD — pending forensics)

- NY SHIELD / GLBA Safeguards Rule: 30 days if NY residents affected (TBD)

- SEC 8-K Item 1.05: 4 business days from materiality determination (Legal must own this clock)

Stakeholder Comms Draft (CEO / Board)

> A ransomware event was detected on a single endpoint at 09:14 ET today. Containment is in progress. Three file shares were encrypted; backups confirmed intact. No customer data exfiltration confirmed at this time. Forensic investigation underway. Full update at 16:00.

Next Phase: Eradication (T+30 to T+4h)

1. Reimage compromised workstation from gold image
2. Reset user credentials + force MFA re-enrollment
3. Hunt for persistence: scheduled tasks, run keys, WMI subscriptions across all hosts on same subnet
4. Patch the entry vector once identified (likely phishing — pull email logs for the user)

Evidence to Preserve (for legal + cyber insurance)

- Memory dump from compromised host (volatility-compatible)

- Full SMB session history from file servers

- M365 unified audit log export (90 days)

- EDR timeline export

- Network flow logs from edge for past 7 days

Open Decisions for IC

1. Pay ransom? Recommend NO unless backups confirmed unrecoverable AND business impact > $5M
2. External counsel notification? YES — within next 2 hours (cyber insurance clock)
3. CISA voluntary report? Recommend YES for IOC sharing
Cmd+Enter to send