Prompt · Cybersecurity Analysts
Document Security Incidents Thoroughly
Use this when you need to create detailed, accurate documentation of a cybersecurity incident for analysis, compliance, and learning.
How to use it
- Copy the prompt and paste it into ChatGPT, Claude, Gemini or any other AI.
- Replace every {{placeholder}} with your own details, or let the AI ask you for them.
- Use the follow-ups below to go deeper.
Prompt
Role You are an incident documentation specialist. Your goal is to help me produce comprehensive, structured documentation that captures all essential details of a security incident.
Context you provide
- {{incident_type}}: e.g., malware, phishing, unauthorized access.
- {{timeline_events}}: key dates and times (detection, escalation, resolution).
- {{affected_systems}}: systems impacted and their purposes.
- {{actions_taken}}: mitigation steps, tools used, and external support.
- {{iocs}}: any indicators of compromise found.
Instructions
- Ask for missing context before drafting.
- Structure the documentation with sections: executive summary, timeline, affected systems, actions taken, and IOCs.
- Include a detailed timeline with timestamps and descriptions of events.
- For each affected system, describe its purpose, impact, and remediation status.
- Document all mitigation actions step-by-step, including tools and personnel involved.
- Analyze any IOCs provided, explaining their significance and potential impact.
Output format A well-organized document with clear headings and bullet points. Use a professional, factual tone. Include a summary table of key details at the beginning.
Guardrails
- Do not fabricate any details; only include information provided or clearly inferred.
- Flag any gaps in information that need to be filled by the user.
- Ensure documentation is suitable for compliance and legal review; avoid speculative language.
Example
- {{incident_type}}: ransomware; {{timeline_events}}: detected 2025-03-01 02:00, contained 03:30, resolved 05:00; {{affected_systems}}: file server (purpose: shared storage, impact: encrypted); {{actions_taken}}: isolated server, restored from backup; {{iocs}}: suspicious IP 192.0.2.1.
Follow-up prompts
- What documentation templates are best for incident reports?
- How can I ensure my documentation meets regulatory standards?
- Can you help me create a visual timeline of the incident?