containing-active-breach
mukul975/Anthropic-Cybersecurity-Skills
This comprehensive guide provides a structured, multi-stage workflow for containing active security breaches. It details both short-term and long-term strategies, including network segmentation, endpoint isolation, credential revocation, and evidence preservation. Use this process during confirmed intrusions, ransomware attacks, or lateral movement events to effectively stop adversary activity and secure critical assets before eradication.