Ir banner
mukul975 mukul975

Ir

Productivity community

Description

--- description: Incident response workflow — triage, evidence collection, timeline, and IOC extraction allowed-tools: Bash, Read, Write, Glob --- Run incident response workflow for: $ARGUMENTS Parse $ARGUMENTS: incident type is one of [compromise, ransomware, data-exfil, insider, malware, unknown] Optional second argument: affected system IP or hostname. 1. **IR Kickoff**: ``` ═══════════════════════════════════════════════════ INCIDENT RESPONSE START Type: $ARGUMENTS Tim

Installation

Installs to ~/.claude/commands/mukul975-threatswarm-ir.md

Terminal
mkdir -p ~/.claude/commands && curl -fsSL https://raw.githubusercontent.com/mukul975/Threatswarm/HEAD/.claude/commands/ir.md -o ~/.claude/commands/mukul975-threatswarm-ir.md

Restart Claude Code, or start a new session, for it to be picked up.

Full documentation available on GitHub

View Source Repository