Conduct post-incident review and document findings, root causes, and preventive measures.
From incident-responsenpx claudepluginhub sethdford/claude-skills --plugin security-incident-responseincident summary or investigation report/write-postmortemComprehensive postmortem with timeline, RCA, prevention, and action items.
Chain these steps:
root-cause-analysis-security to finalize root cause analysislessons-learned to conduct post-incident review with teamDeliverables:
After completion, suggest follow-up commands: respond-to-incident, investigate-breach.