Security Breach Incident-Response Runbook Prompt
Generate a security-breach response runbook structured around containment, eradication, and recovery — with evidence preservation, scoped isolation, and legal/notification gates so a breach is handled without destroying forensics or tipping off the attacker.
- Target user
- Security engineers, SREs, and incident responders handling breaches
- Difficulty
- Advanced
- Tools
- Claude, ChatGPT
The prompt
You are a security incident responder who has handled real breaches and knows that hasty cleanup destroys forensic evidence and that wiping a box before scoping the intrusion just invites the attacker back. I will provide: - The detection signal (alert, anomaly, report) and affected systems - Our environment (cloud/on-prem, identity provider, logging/SIEM) - Whether the attacker may still have active access - Legal, regulatory, and customer-notification obligations Your job: 1. **Declare and assemble** — invoke the security incident process, pull in the right roles (security lead, IC, legal, comms), and open a restricted-access incident channel separate from general ops. 2. **Containment first, without tipping off** — isolate affected systems (network segmentation, credential revocation, session invalidation) in a way that limits attacker movement while preserving the live state for forensics. Decide consciously between fast-isolate and monitor-to-learn. 3. **Preserve evidence** — snapshot disks/memory, export logs to immutable storage, and record chain-of-custody before any cleanup, since evidence may be needed for legal action and root-cause. 4. **Scope the intrusion** — determine the entry point, lateral movement, what data/credentials were accessed, dwell time, and whether persistence mechanisms (backdoors, rogue accounts, keys) were planted. 5. **Eradication** — remove the attacker's access comprehensively: rotate all potentially-exposed credentials and keys, remove persistence, patch the entry vector. Eradicate only after scoping, or you will miss footholds. 6. **Recovery** — rebuild from known-good (not just clean-in-place), restore service, and heighten monitoring for re-entry attempts during a watch period. 7. **Notification gates** — identify regulatory breach-notification clocks (e.g., 72-hour windows), customer/contractual obligations, and law-enforcement engagement, with legal sign-off gates. Output as: (a) the runbook in containment → eradication → recovery phases, (b) the evidence-preservation and chain-of-custody checklist, (c) a scoping worksheet (entry, lateral movement, data accessed, persistence), (d) a credential/key rotation inventory, (e) the notification-obligation table with clocks and sign-off gates. Bias toward: preserving evidence before cleanup, scoping fully before eradicating, comprehensive credential rotation, legal involvement early, rebuild over clean-in-place.
Run this prompt with AI
Test it, get an AI-improved version, or compare models — live in the Prompt Workspace. No copy-paste.
Related prompts
-
Expired TLS Certificate Incident Triage Prompt
Triage a live outage caused by an expired or mis-issued TLS certificate — identify every affected endpoint, the renewal path, and a safe emergency reissue plan without breaking pinning or chains.
-
Live Incident Evidence Preservation Checklist Prompt
Generate a checklist for capturing volatile diagnostic evidence during a live incident before it is lost to restarts or rotation
-
Incident Timeline Reconstruction Prompt
Reconstruct an accurate, evidence-backed incident timeline from scattered logs, deploys, pages, and chat — disambiguating timezones and correlating cause with effect for the postmortem.
-
Capacity Saturation Early-Warning Design Prompt
Design leading saturation alerts — for pools, queues, memory headroom, and resource trends — that fire while there is still time to act, so the team gets paged before a slow capacity creep becomes a 3am outage instead of after users already feel it.
More Incident Response prompts & error guides
Browse every Incident Response prompt and troubleshooting guide in one place.
Reading prompts? Get all 500 in one free PDF
500 battle-tested, copy-paste AI prompts engineered by a senior systems engineer — every one with fill-in placeholders and safety/back-out notes. Drop your email and it's yours.
- 500 prompts: Linux · Kubernetes · Terraform · OpenStack · GitLab · Docker · Monitoring · Incident Response
- Instant PDF download — yours free, forever
- Plus one practical AI-workflow email a week (no spam)
Single opt-in · unsubscribe anytime · no spam.