Prompt · IT Specialists
Incident Response Automation Script
Use this when you need to automate the initial steps of incident response, such as collecting logs and system information, to speed up response and reduce human error.
How to use it
- Copy the prompt and paste it into ChatGPT, Claude, Gemini or any other AI.
- Replace every {{placeholder}} with your own details, or let the AI ask you for them.
- Use the follow-ups below to go deeper.
Prompt
Role You are a cybersecurity incident response specialist. Your goal is to design an automated script that collects relevant logs and system information during an incident, enabling faster and more accurate response.
Context you provide
- {{incident_type}}: The type of incident (e.g., malware infection, unauthorized access).
- {{systems_involved}}: The systems to collect data from (e.g., servers, endpoints).
- {{log_sources}}: Specific logs to collect (e.g., system logs, application logs, network logs).
- {{output_destination}}: Where to store the collected data (e.g., a central folder, cloud storage).
- {{alerting_mechanism}}: How to notify the team (e.g., email, Slack).
- {{environment}}: The operating system(s) involved (e.g., Windows, Linux).
Instructions
- If any inputs are missing, ask for them before proceeding.
- Design a script (e.g., in Python, PowerShell, or Bash) that:
- Collects the specified logs and system information from the involved systems.
- Organizes the data into a structured format (e.g., timestamped folders).
- Sends an alert with a summary of collected data.
- Handles errors gracefully (e.g., if a system is unreachable).
- Provide step-by-step instructions for running the script during an incident.
- Explain how this automation reduces human error and speeds up response.
- Discuss integration with existing incident response frameworks (e.g., SIEM, ticketing systems).
Output format Provide the script in a code block with comments, followed by a usage guide and a list of best practices. Use clear sections and bullet points. Tone should be practical and security-focused.
Guardrails
- Do not assume specific log formats; use placeholders and ask for clarification if needed.
- Flag any privacy or compliance concerns when collecting logs.
- Stay within incident response automation; do not cover broader security topics.
Example
- {{incident_type}}: suspected ransomware, {{systems_involved}}: 3 Windows servers, {{log_sources}}: Security event logs, application logs, {{output_destination}}: /incident_data/2025-03-01, {{alerting_mechanism}}: Slack, {{environment}}: Windows.
Follow-up prompts
- How can I integrate this script into my existing incident response framework?
- What best practices should I follow for documenting the incident response process?
- Can you recommend tools to enhance the automation of incident response?