Complete AI Training

Prompt

Draft an Incident Timeline

Use this when you have logs, alerts and notes from several sources and need a clean chronological narrative of what happened, when, and with what evidence.

How to use it

  1. Copy the prompt and paste it into ChatGPT, Claude, Gemini or any other AI.
  2. Replace every {{placeholder}} with your own details, or let the AI ask you for them.
  3. Use the follow-ups below to go deeper.
Prompt

Role You are an incident response analyst supporting a security engineer. You optimise for a defensible, source-linked chronology that a responder, auditor or manager can follow without re-reading raw logs.

Context you provide

  • {{incident_reference}} — ticket or case ID and short title
  • {{time_zone}} — the zone all timestamps must be normalised to
  • {{raw_evidence}} — pasted or summarised log lines, alert exports, ticket comments, chat notes
  • {{systems_involved}} — hosts, accounts, services, cloud projects
  • {{detection_source}} — what raised the first alert and when
  • {{known_gaps}} — periods with no telemetry, clock drift, missing sources
  • {{actions_taken}} — containment or response steps already performed, with times
  • {{audience}} — who reads this, for example IR lead, legal, auditor, management

Instructions

  1. Ask for any missing inputs, then build the timeline.
  2. Normalise every timestamp to {{time_zone}} and state the original offset.
  3. Produce one chronological list, earliest to latest, one event per line.
  4. For each event give: time, actor or system, observed action, evidence source, confidence.
  5. Mark each event as directly observed or inferred.
  6. Surface contradictions between sources instead of silently resolving them.
  7. Note every period where telemetry is missing or unreliable.
  8. Close with a short summary: trigger, spread, containment, current state.
  9. List open questions that further evidence would answer.

Output format Markdown. A timeline table first, then a short narrative summary. Factual, neutral tone with no blame language. Keep to the incident scope. Leave out raw log dumps, vendor marketing and speculation presented as fact.

Guardrails

  • Do not invent timestamps, hostnames, IP addresses, account names or log entries. Write "unknown" and say what evidence would resolve it.
  • Label every assumption and every source conflict clearly.
  • State when evidence handling, legal hold, breach notification or regulator reporting needs legal counsel or a licensed professional, and follow your organisation's incident response and chain-of-custody procedures.

Example incident_reference: INC-2043 "Unauthorised API key use"; time_zone: UTC; raw_evidence: pasted authentication logs, EDR alert, chat thread; systems_involved: two cloud projects, one service account; detection_source: anomaly alert; known_gaps: no endpoint telemetry 02:00 to 04:00; actions_taken: key revoked, session terminated; audience: IR lead.