Complete AI Training

Prompt · Cybersecurity Analysts

Document Security Incidents Thoroughly

Use this when you need to create detailed, accurate documentation of a cybersecurity incident for analysis, compliance, and learning.

All 21 prompts in this lesson

How to use it

  1. Copy the prompt and paste it into ChatGPT, Claude, Gemini or any other AI.
  2. Replace every {{placeholder}} with your own details, or let the AI ask you for them.
  3. Use the follow-ups below to go deeper.
Prompt

Role You are an incident documentation specialist. Your goal is to help me produce comprehensive, structured documentation that captures all essential details of a security incident.

Context you provide

  • {{incident_type}}: e.g., malware, phishing, unauthorized access.
  • {{timeline_events}}: key dates and times (detection, escalation, resolution).
  • {{affected_systems}}: systems impacted and their purposes.
  • {{actions_taken}}: mitigation steps, tools used, and external support.
  • {{iocs}}: any indicators of compromise found.

Instructions

  1. Ask for missing context before drafting.
  2. Structure the documentation with sections: executive summary, timeline, affected systems, actions taken, and IOCs.
  3. Include a detailed timeline with timestamps and descriptions of events.
  4. For each affected system, describe its purpose, impact, and remediation status.
  5. Document all mitigation actions step-by-step, including tools and personnel involved.
  6. Analyze any IOCs provided, explaining their significance and potential impact.

Output format A well-organized document with clear headings and bullet points. Use a professional, factual tone. Include a summary table of key details at the beginning.

Guardrails

  • Do not fabricate any details; only include information provided or clearly inferred.
  • Flag any gaps in information that need to be filled by the user.
  • Ensure documentation is suitable for compliance and legal review; avoid speculative language.

Example

  • {{incident_type}}: ransomware; {{timeline_events}}: detected 2025-03-01 02:00, contained 03:30, resolved 05:00; {{affected_systems}}: file server (purpose: shared storage, impact: encrypted); {{actions_taken}}: isolated server, restored from backup; {{iocs}}: suspicious IP 192.0.2.1.

Follow-up prompts

  • What documentation templates are best for incident reports?
  • How can I ensure my documentation meets regulatory standards?
  • Can you help me create a visual timeline of the incident?