
Incident Response Coordinator
Orchestrate rapid incident triage, forensic preservation, and team coordination
What You Can Do
You can rapidly establish incident scope, preserve critical forensic evidence, and coordinate technical and non-technical teams through structured decision frameworks. This skill helps you distinguish critical incidents from false alerts within minutes, document evidence chains for regulatory compliance, reconstruct attack timelines to identify dwell time and attack vectors, and generate clear stakeholder communications that balance operational security with transparency.
Features
Distinguishes critical incidents from benign alerts within 5 minutes using structured decision trees
Ensures chain-of-custody compliance and forensic viability for legal/regulatory proceedings
Identifies attack vectors, dwell time, and lateral movement using fragmented log sources
Delivers actionable updates to executives and teams without exposing operational details
Balances speed of containment against forensic preservation requirements
Generates records that satisfy PCI-DSS, HIPAA, SOC 2, and other regulatory frameworks
Determines when to involve law enforcement, external responders, or cyber insurance
Synchronizes parallel investigations across security, infrastructure, and business continuity teams
Example Output
Incident Triage Output:
- Incident ID: INC-2024-0847
- Severity: CRITICAL (confirmed lateral movement to 12 systems)
- Initial Assessment: Ransomware — likely LockBit variant based on file signatures
- Immediate Actions: Isolate affected subnets, preserve memory images, notify legal
Evidence Checklist (Chain of Custody):
- ✓ Memory captures from 8 affected hosts (timestamps, hash verification)
- ✓ Network packet captures from perimeter (24-hour window)
- ✓ Log exports from EDR platform (quarantined, read-only)
- ✓ Forensic images initiated (sequential block-by-block)
Attack Timeline:
- 2024-01-15 14:22 UTC — Initial access via compromised VPN credentials (credential stuffing detected in auth logs)
- 2024-01-15 15:47 UTC — Lateral movement to Domain Controller (Kerberos delegation abuse)
- 2024-01-16 03:14 UTC — Ransomware payload deployment across file servers
- Dwell time: 12 hours 52 minutes
Stakeholder Update (Executive Summary): "We identified and contained a ransomware incident affecting file storage systems. Operations teams isolated affected systems within 2 hours of detection. No customer data was exfiltrated. Forensic investigation is underway with external IR firm."
What's Included
- SKILL.md instruction file with incident response orchestration framework:
- Incident triage decision tree (flowchart: alert → scope → severity → initial actions):
- Evidence collection checklist with chain-of-custody tracking template:
- Incident communication matrix (templates for executives, board, law enforcement, customers):
- Timeline reconstruction worksheet (log source prioritization, event correlation guide):
- Containment vs. preservation trade-off matrix (decision framework for containment approach):
- Post-incident documentation template (regulatory compliance checklist for PCI-DSS, HIPAA, SOC 2):
Who It's For
- Incident response managers — Coordinating triage and investigation workflows across distributed teams
- Security operations center (SOC) leads — Escalating critical incidents with complete forensic records
- Forensic investigators — Reconstructing attack timelines and preserving evidence for legal proceedings
- Chief information security officers — Managing incident response quality and regulatory compliance documentation
- Internal security teams — Handling incidents without external responders (first-responder triage and initial investigation)
Best For
- Incident triage and severity assessment within the first hour of detection
- Evidence preservation and chain-of-custody documentation for forensic/legal review
- Reconstructing attack timelines from fragmented logs and system artifacts
- Coordinating parallel investigations across technical teams (network, endpoint, cloud, application)
- Generating compliant incident reports for regulatory bodies (PCI-DSS, HIPAA, SOC 2 audits)
- Drafting stakeholder communications (executive briefings, customer notifications, law enforcement coordination)







