Tracecat
Respond
RS.MA

Incident Management

Responses to detected cybersecurity incidents are managed

Tools for incident management

Hosted MCP servers your agents can use for these controls.

Starter prompts

Paste into Claude Code, Microsoft Copilot, or Codex connected to Tracecat MCP, and build it out together.

Triage and validate incident reports

Build me an incident intake workflow in Tracecat. Accept reports from the security inbox in Gmail, a Slack shortcut, and tool webhooks. Have an agent validate each report, dedupe it against open cases, fill the required case fields, and close obvious false alarms with a polite explanation to the reporter. Everything else becomes a case in the triage queue. First help me understand how this maps to RS.MA-02 and why validation before assignment protects the on-call analyst. Ask me what minimum fields a workable case needs. Talk me through which false-alarm patterns are safe to auto-close.

Categorize and prioritize incidents

Build me a case classification automation in Tracecat. When a case enters triage, have an agent read the evidence, set the incident category from our taxonomy, and score priority from asset criticality, data sensitivity, and spread. Route the case to the owning queue, and page through PagerDuty when priority crosses our threshold. First help me understand how this maps to RS.MA-03 and how a consistent taxonomy improves both response and reporting. Ask me what categories and priority levels we use today. Talk me through auditing the agent's classifications so trust builds over time.

Escalate incidents on clear criteria

Build me an escalation automation in Tracecat. Encode our escalation criteria: priority level, blast radius, regulated data, or response time exceeded, and when a case meets one, open an Incident.io incident, page the incident commander through PagerDuty, and post the case summary with the timeline so far. Record what triggered the escalation on the case. First help me understand how this maps to RS.MA-04 and why escalation criteria should be decided before the bad day, not during it. Ask me who can declare and who must be told. Talk me through de-escalation when the trigger turns out to be wrong.

Apply recovery initiation criteria

Build me a recovery gate in Tracecat. For active incidents, track the recovery criteria as case tasks: containment confirmed, root cause known well enough, and eradication verified. When all pass, notify the incident commander in Slack that recovery can begin, kick off the recovery checklist, and record the decision and timestamp on the case. First help me understand how this maps to RS.MA-05 and why starting recovery too early reinfects environments. Ask me who owns the recovery decision today. Talk me through which criteria can be machine-verified and which need human sign-off.

Controls

  • RS.MA-01
    IR-6
    IR-7
    IR-8
    SR-3
    SR-8

    The incident response plan is executed in coordination with relevant third parties once an incident is declared

  • RS.MA-02
    IR-4
    IR-5
    IR-6

    Incident reports are triaged and validated

  • RS.MA-03
    IR-4
    IR-5
    IR-6

    Incidents are categorized and prioritized

  • RS.MA-04
    IR-4
    IR-5
    IR-6
    IR-7

    Incidents are escalated or elevated as needed

  • RS.MA-05
    IR-4
    IR-8

    The criteria for initiating incident recovery are applied

Control text and SP 800-53 Rev 5 references from the official NIST CSF 2.0 and OLIR releases.

Automate incident management with agents

Paste an example into your coding assistant and an agent builds the automation around your tools.

All controls