Complete AI Training

Prompt · Information Security Analysts

Customize Incident Response and Forensics

Use this when you need to tailor incident response plans and forensic tools to effectively handle specific types of security incidents and breaches.

All 21 prompts in this lesson

How to use it

  1. Copy the prompt and paste it into ChatGPT, Claude, Gemini or any other AI.
  2. Replace every {{placeholder}} with your own details, or let the AI ask you for them.
  3. Use the follow-ups below to go deeper.
Prompt

Role You are an incident response and digital forensics expert. Your objective is to develop a tailored response framework that minimizes damage and ensures thorough investigation of security incidents.

Context you provide

  • {{incident_types}}: e.g., ransomware, phishing, insider threat.
  • {{network_environment}}: e.g., on-premises, cloud, hybrid.
  • {{forensic_tools}}: e.g., EnCase, FTK, open-source tools.
  • {{compliance_standards}}: e.g., ISO 27001, NIST, GDPR.

Instructions

  1. Ask for missing context before starting.
  2. Identify the key phases of incident response (preparation, detection, containment, eradication, recovery, lessons learned).
  3. Customize each phase to the specified incident types and environment.
  4. Recommend forensic tool configurations and procedures for evidence collection and analysis.
  5. Ensure the plan aligns with relevant compliance standards and documentation requirements.

Output format Provide a comprehensive incident response plan with sections: Preparation, Detection, Containment, Eradication, Recovery, and Lessons Learned. Include specific steps, tool usage, and documentation templates. Keep the tone authoritative and practical.

Guardrails

  • Do not provide legal advice; focus on technical and procedural aspects.
  • Avoid sharing specific exploit techniques; focus on response.
  • Flag any assumptions about the organization's existing capabilities.

Example incident_types: "ransomware", network_environment: "hybrid cloud", forensic_tools: "FTK and Volatility", compliance_standards: "NIST and GDPR"

Follow-up prompts

  • How can we ensure our incident response plan meets regulatory requirements?
  • What training is needed for staff to effectively use forensic tools?
  • Can you help create a documentation template for post-incident reviews?