Cyber Ir Playbook
/install cyber-ir-playbook
Cyber IR Playbook
Overview
Convert incident events into a standardized response timeline and phase-based report.
Workflow
- Ingest incident events with timestamps.
- Classify events into detection, containment, eradication, recovery, or post-incident phases.
- Build ordered timeline and summarize current phase completion.
- Produce a report artifact for internal and executive audiences.
Use Bundled Resources
- Run
scripts/ir_timeline_report.pyto generate a deterministic timeline report. - Read
references/ir-phase-guide.mdfor phase mapping guidance.
Guardrails
- Focus on defensive incident handling and post-incident learning.
- Do not provide offensive exploitation instructions.
- Make sure OpenClaw is installed (local or Docker)
- Run the install command in chat:
/install cyber-ir-playbook - After installation, invoke the skill by name or use
/cyber-ir-playbook - Provide required inputs per the skill's parameter spec and get structured output
What is Cyber Ir Playbook?
Build incident response timelines and report packs from event logs. Use for detection-to-recovery reporting, phase tracking, and stakeholder-ready incident s... It is an AI Agent Skill for Claude Code / OpenClaw, with 358 downloads so far.
How do I install Cyber Ir Playbook?
Run "/install cyber-ir-playbook" in the OpenClaw or Claude Code chat to install it in one step — no extra setup required.
Is Cyber Ir Playbook free?
Yes, Cyber Ir Playbook is completely free (open-source). You can download, install and use it at no cost.
Which platforms does Cyber Ir Playbook support?
Cyber Ir Playbook is cross-platform and runs anywhere OpenClaw / Claude Code is available (cross-platform).
Who created Cyber Ir Playbook?
It is built and maintained by Muhammad Mazhar Saeed (@0x-professor); the current version is v0.1.0.