Works with
Incident Response
Use when a security incident has been detected or declared and needs classification, triage, escalation path determination, and forensic evidence collection. Covers SEV1-SEV4 classification, false positive filtering, incident taxonomy, and NIST SP 800-61 lifecycle.
Optimized workflow
This edition turns the source methodology into a repeatable agent workflow with explicit inputs, checkpoints and deliverables.
Quality standard
- Confirm scope and missing inputs before execution
- Ground decisions in available evidence and preserve source constraints
- Return an actionable result with assumptions, risks and next steps
Agent compatibility
The same core method is packaged for Claude, Codex, GPT, Gemini, Cursor and OpenCode.
Permissions & security
Source verified · conversion tested · security signals reviewed