CtrlK
BlogDocsLog inGet started
Tessl Logo

building-soc-playbook-for-ransomware

Builds a structured SOC incident response playbook for ransomware attacks covering detection, containment, eradication, and recovery phases with specific SIEM queries, isolation procedures, and decision trees. Use when SOC teams need formalized response procedures for ransomware incidents aligned to NIST SP 800-61 and MITRE ATT&CK ransomware techniques.

65

Quality

82%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide
SecuritybySnyk

Low

Low-risk findings worth noting

SKILL.md
Quality
Evals
Security

Quality

Content

65%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

Highly actionable content — real, executable queries and API calls across the major SIEM/EDR platforms — undermined by three structural issues: sections padding with knowledge Claude already has, missing validation checkpoints around destructive containment actions, and orphaned bundle files (api-reference.md, agent.py) that the body never points to.

Suggestions

Add explicit validation checkpoints after destructive/batch operations, e.g. verify the host shows as contained in the EDR console and re-scan for C2 beacons before proceeding to enterprise-wide IOC sweeps.

Reference the existing bundle files from the body — e.g. an 'Automation' section pointing to scripts/agent.py and references/api-reference.md for API-driven execution of the containment and IOC-scan steps.

Trim or remove the 'Key Concepts' and 'Tools & Systems' sections, which re-explain concepts (Double Extortion, Kill Chain, RTO/RPO) and vendor products Claude already knows.

DimensionReasoningScore

Conciseness

The workflow itself is dense and lean, but the "Key Concepts" table (Double Extortion, Dwell Time, Kill Chain, Immutable Backup, RTO/RPO) and "Tools & Systems" section re-explain concepts and vendor products Claude already knows — two full sections of unnecessary explanation. Not 4: that over-explanation is more than minor; not 2 because the bulk of the body is genuinely efficient executable content.

3 / 5

Actionability

Fully executable, copy-paste-ready guidance for the common cases: complete Splunk SPL and Elastic EQL detection queries, a working CrowdStrike curl call, MDE PowerShell isolation, firewall rule syntax, and evidence-collection commands. Not 4: the only gaps are inherent template placeholders (device IDs, hashes), not missing steps or pseudocode.

5 / 5

Workflow Clarity

Six steps are clearly sequenced with a decision tree for escalation, but the workflow involves destructive/batch operations (enterprise-wide SMB block, disabling AD accounts, krbtgt reset, host isolation) with no validation checkpoints — nothing verifies isolation succeeded or confirms scope before the next destructive action. Per the rubric's cap for destructive/batch operations without validation, this cannot score above 3; the recovery step's 'Verify backup integrity'/'Validate restored systems' checks are not enough to lift it.

3 / 5

Progressive Disclosure

The body is well-sectioned, but the actual bundle contains references/api-reference.md and scripts/agent.py (an automation agent with CLI usage and API functions) that are never mentioned anywhere in the body — provided references are completely un-signaled rather than merely unclear. Not 4: good structure alone doesn't qualify when navigation to existing bundle files is absent; not 2 because the body's own structure is solid, not minimal.

3 / 5

Total

14

/

20

Passed

Description

92%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

A strong description: third person, concrete multi-action capability statement, explicit 'Use when' trigger clause, and a clearly demarcated niche. Only weakness is slightly narrow trigger-term vocabulary (no 'runbook'/'IR plan' style synonyms).

DimensionReasoningScore

Specificity

"Builds a structured SOC incident response playbook... covering detection, containment, eradication, and recovery phases with specific SIEM queries, isolation procedures, and decision trees" names multiple concrete actions (phases, SIEM queries, isolation, decision trees) with comprehensive coverage. Not 4: coverage is broad and every named action is concrete, not just several with minor gaps.

5 / 5

Completeness

Explicitly answers what ("Builds a structured SOC incident response playbook for ransomware attacks covering detection, containment, eradication, and recovery...") and when ("Use when SOC teams need formalized response procedures for ransomware incidents aligned to NIST SP 800-61 and MITRE ATT&CK") with concrete trigger phrases. Not 4: the 'when' clause is fully explicit, not merely present-but-imprecise.

5 / 5

Trigger Term Quality

Includes natural phrases users would say — "SOC", "ransomware", "incident response", "playbook", "NIST SP 800-61", "MITRE ATT&CK" — with good coverage. Not 5: common synonyms a user might naturally say are missing (e.g., "runbook", "IR plan", "tabletop", "breach response").

4 / 5

Distinctiveness Conflict Risk

A clear niche — building ransomware-specific SOC response playbooks aligned to NIST/ATT&CK — with distinct triggers that would not fire for adjacent skills (malware analysis, phishing response, backup administration). Not 4: overlap risk with generic IR-documentation skills is minimal given the ransomware-specific framing.

5 / 5

Total

19

/

20

Passed

Validation

93%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation — 15 / 16 Passed

Validation for skill structure

CriteriaDescriptionResult

frontmatter_unknown_keys

Unknown frontmatter key(s) found; consider removing or moving to metadata

Warning

Total

15

/

16

Passed

Repository
mukul975/Anthropic-Cybersecurity-Skills
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.