mirror of
https://github.com/mukul975/Anthropic-Cybersecurity-Skills.git
synced 2026-09-04 07:20:50 +03:00
Complete folder anatomy for all 649 cybersecurity skills + update LICENSE to Mahipal
- Add scripts/agent.py and references/api-reference.md to all remaining skills - Update all 648 LICENSE files: copyright now reads 'Mahipal' - Add implementing-security-monitoring-with-datadog (new skill with full anatomy) - All 649 skills now have: SKILL.md, LICENSE, scripts/agent.py, references/api-reference.md
This commit is contained in:
@@ -0,0 +1,49 @@
|
||||
# API Reference: Triaging Security Incidents with IR Playbooks
|
||||
|
||||
## Incident Classification Types
|
||||
|
||||
| Type | Keywords | Default Severity | Playbook |
|
||||
|------|----------|-----------------|----------|
|
||||
| Malware | trojan, ransomware, c2, beacon | High | malware-infection-playbook |
|
||||
| Phishing | credential harvest, BEC, spear-phishing | Medium | phishing-response-playbook |
|
||||
| Data Exfiltration | DLP, dns tunnel, large upload | Critical | data-exfiltration-playbook |
|
||||
| Unauthorized Access | brute force, lateral movement | High | unauthorized-access-playbook |
|
||||
| Denial of Service | DDoS, SYN flood, volumetric | High | ddos-response-playbook |
|
||||
| Insider Threat | policy violation, terminated user | High | insider-threat-playbook |
|
||||
| Web Attack | SQLi, XSS, web shell, RCE | High | web-attack-playbook |
|
||||
|
||||
## Severity Matrix
|
||||
|
||||
| Context Factor | Severity Override |
|
||||
|----------------|-------------------|
|
||||
| Crown jewel system affected | Critical |
|
||||
| Active exploitation confirmed | Critical |
|
||||
| Multiple systems (>5) affected | High |
|
||||
| Single system affected | Medium |
|
||||
| Reconnaissance only | Low |
|
||||
| Minor policy violation | Informational |
|
||||
|
||||
## Escalation Paths
|
||||
|
||||
| Severity | Response Time | Escalation |
|
||||
|----------|---------------|------------|
|
||||
| Critical | 15 minutes | IR Team + CISO + Legal |
|
||||
| High | 1 hour | SOC Tier 2 + IR Team |
|
||||
| Medium | 4 hours | SOC Tier 2 |
|
||||
| Low | 24 hours | SOC Tier 1 |
|
||||
| Informational | Next business day | SOC Tier 1 |
|
||||
|
||||
## Python Libraries
|
||||
|
||||
| Library | Version | Purpose |
|
||||
|---------|---------|---------|
|
||||
| `json` | stdlib | Alert parsing and report generation |
|
||||
| `enum` | stdlib | Severity level enumeration |
|
||||
| `pathlib` | stdlib | Output directory management |
|
||||
| `datetime` | stdlib | Triage timestamps |
|
||||
|
||||
## References
|
||||
|
||||
- NIST SP 800-61r2: https://csrc.nist.gov/publications/detail/sp/800-61/rev-2/final
|
||||
- SANS Incident Handler's Handbook: https://www.sans.org/white-papers/33901/
|
||||
- TheHive: https://thehive-project.org/
|
||||
Reference in New Issue
Block a user