Atlas / Skills / mukul975 / Building Malware Incident Communication Template

Building Malware Incident Communication TemplateCAUTION

skills/mukul975/building-malware-incident-communication-template

817 structured cybersecurity skills for AI agents · Mapped to 6 frameworks: MITRE ATT&CK, NIST CSF 2.0, MITRE ATLAS, D3FEND, NIST AI RMF & MITRE F3 (Fight Fraud) · agentskills.io standard · Works with Claude Code, GitHub Copilot, Codex CLI, Cursor, Gemini CLI & 20+ platforms · 29 security domains ·

Verdict
CAUTION
Grade
B
Trust score
89 /100
Version
1.0
Hosts
—
License
Apache-2.0
Stars
33,870
01

Overview

817 structured cybersecurity skills for AI agents · Mapped to 6 frameworks: MITRE ATT&CK, NIST CSF 2.0, MITRE ATLAS, D3FEND, NIST AI RMF & MITRE F3 (Fight Fraud) · agentskills.io standard · Works with Claude Code, GitHub Copilot, Codex CLI, Cursor, Gemini CLI & 20+ platforms · 29 security domains ·

Read from source at commit 6c59587be632OBSERVED · 2026-10-07
02

What it tells the agent

The instruction file, verbatim from the audited commit — this is the text the model reads, and the surface the audit's instruction layer examines. Quoted here so you can judge it without cloning anything.

---
name: building-malware-incident-communication-template
description: Build structured communication templates for malware incidents (ransomware,
  wiper, trojan, worm), covering internal stakeholder notifications, executive briefings,
  technical advisories for IT teams, customer notifications, and regulatory disclosures,
  with severity-based escalation procedures. Use when drafting or standardizing incident
  communications and notification workflows for a malware outbreak.
domain: cybersecurity
subdomain: incident-response
tags:
- incident-communication
- malware-response
- stakeholder-notification
- crisis-communication
- executive-briefing
- regulatory-disclosure
mitre_attack:
- T1486
- T1490
- T1657
- T1041
- T1566
version: '1.0'
author: mahipal
license: Apache-2.0
nist_csf:
- RS.MA-01
- RS.MA-02
- RS.AN-03
- RC.RP-01
---

# Building Malware Incident Communication Template

## Overview

Effective communication during malware incidents is critical for coordinated response, stakeholder management, and regulatory compliance. A structured communication framework ensures the right people receive appropriate information at the right time, preventing panic while maintaining transparency. Communication templates should cover internal escalation, executive briefings, technical advisories for IT teams, customer notifications, regulatory disclosures, and media statements. The framework must account for different malware types (ransomware, wiper, trojan, worm) and severity levels that drive escalation speed and audience.


## When to Use

- When deploying or configuring building malware incident communication template capabilities in your environment
- When establishing security controls aligned to compliance requirements
- When building or improving security architecture for this domain
- When conducting security assessments that require this implementation

## Prerequisites

- Familiarity with incident response concepts and tools
- Access to a test or lab environment for safe execution
- Python 3.8+ with required dependencies installed
- Appropriate authorization for any testing activities

## Communication Framework

### Severity Classification

| Severity | Description | Notification Timeline | Audience |
|----------|-------------|----------------------|----------|
| P1 - Critical | Ransomware, wiper, or widespread infection affecting business operations | Within 15 minutes | CISO, CEO, Legal, Board (if applicable) |
| P2 - High | Targeted malware on critical systems, data exfiltration suspected | Within 1 hour | CISO, IT Director, Legal |
| P3 - Medium | Contained malware infection, limited spread | Within 4 hours | Security Manager, IT Director |
| P4 - Low | Single endpoint infection, quickly contained | Within 24 hours | Security Team Lead |

### Communication Channels

| Channel | Use Case | Security Level |
|---------|----------|---------------|
| Out-of-band phone calls | Initial critical notifications | Highest |
| Encrypted messaging (Signal) | Real-time IR team coordination | High |
| Secure email (encrypted) | Formal notifications, documentation | High |
| War room (physical/virtual) | Ongoing incident coordination | Medium |
| Incident ticketing system | Status tracking and documentation | Medium |
| Company intranet | Broad employee communication | Standard |

## Template 1: Initial Incident Notification (Internal)

```
SUBJECT: [SEVERITY] Malware Incident - Initial Notification - [DATE/TIME UTC]

CLASSIFICATION: CONFIDENTIAL - IR TEAM ONLY

INCIDENT ID: IR-[YEAR]-[NUMBER]
DETECTION TIME: [YYYY-MM-DD HH:MM UTC]
NOTIFICATION TIME: [YYYY-MM-DD HH:MM UTC]
SEVERITY: [P1/P2/P3/P4]

SUMMARY:
A malware incident has been detected affecting [NUMBER] systems in
[DEPARTMENT/LOCATION]. The malware has been identified as [TYPE] with
[KNOWN/UNKNOWN] characteristics.

CURRENT IMPACT:
- Systems affected: [COUNT and DESCRIPTION]
- Business functions impacted: [LIST]
- Data at risk: [DESCRIPTION]
- Current spread status: [CONTAINED/SPREADING/UNKNOWN]

IMMEDIATE ACTIONS TAKEN:
1. [ACTION - e.g., Affected endpoints isolated from network]
2. [ACTION - e.g., EDR containment policies activated]
3. [ACTION - e.g., Security team mobilized]

NEXT STEPS:
1. [PLANNED ACTION with TIMELINE]
2. [PLANNED ACTION with TIMELINE]

INCIDENT COMMANDER: [NAME]
CONTACT: [PHONE/ENCRYPTED CHANNEL]

NEXT UPDATE: [TIME] or sooner if situation changes

---
Do not forward this notification outside the IR team.
```

## Template 2: Executive Briefing

```
SUBJECT: Executive Briefing - Malware Incident IR-[YEAR]-[NUMBER]

FOR: [CEO / CISO / CIO / Board]
FROM: [Incident Commander]
DATE: [DATE]
UPDATE: [#]

SITUATION SUMMARY:
[2-3 sentences describing the incident in business terms]

BUSINESS IMPACT:
- Revenue impact: [ESTIMATED/NONE/UNDER ASSESSMENT]
- Operational impact: [DESCRIPTION]
- Customer impact: [DESCRIPTION]
- Regulatory implications: [DESCRIPTION]

CURRENT STATUS: [DETECTED / CONTAINED / ERADICATING / RECOVERING]

KEY DECISIONS NEEDED:
1. [DECISION with context and recommendation]
2. [DECISION with context and recommendation]

TIMELINE:
- [TIME]: Incident detected
- [TIME]: Containment initiated
- [TIME]: [MILESTONE]
- [TIME]: Estimated recovery (if known)

EXTERNAL COMMUNICATION STATUS:
- Regulatory notification: [REQUIRED/SUBMITTED/NOT REQUIRED]
- Customer notification: [REQUIRED/PLANNED/NOT REQUIRED]
- Law enforcement: [ENGAGED/PLANNED/NOT APPLICABLE]

RESOURCE REQUIREMENTS:
- [RESOURCE NEED - e.g., External IR firm engagement]
- [RESOURCE NEED - e.g., Additional hardware for rebuild]

NEXT UPDATE: [TIME]
```

## Template 3: Technical Advisory for IT Teams

```
SUBJECT: TECHNICAL ADVISORY - [MALWARE NAME] - Immediate Action Required

SEVERITY: [CRITICAL/HIGH/MEDIUM]
DATE: [DATE/TIME UTC]
ADVISORY ID: TA-[YEAR]-[NUMBER]

THREAT DESCRIPTION:
[Technical description of the malware, behavior, and indicators]

AFFECTED SYSTEMS:
- Operating Systems: [LIST]
- Applications: [LIST]
- Network segments: [LIST]

INDICATOR
03

Trust audit

CAUTIONgrade B · trust 89/100 Install with care. The audit found things worth knowing before you trust its output.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codeWARN
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfacePASS
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
none-observed
Network
UNDECLARED (2 observation(s))
Shell
none-observed
Dependencies
pinned
Secrets in source
none-found

Findings (3)

MEDIUMNetwork egress · net.beacon_words · CWE-200, CWE-319
scripts/agent.py:22
"trojan": {"impact": "Unauthorized access, data exfiltration", "containment": "Block C2 IPs, isolate hosts",
MEDIUMNetwork egress · net.beacon_words · CWE-200, CWE-319
scripts/agent.py:26
"infostealer": {"impact": "Credential theft, PII exposure", "containment": "Block exfiltration channels, isolate hosts",
INFOPrompt injection · scope.undeclared_network · CWE-94, CWE-1427
<declared scope>
network use found in code, not declared in the description
Why it matters. the description does not admit a capability the code has
Fix. declare network use in the description, or remove it

Gates applied: no_behavioural_pass.

Audited 2026-10-07 · audit v0.4.1 · source sha 6c59587be632full audit observations/trust-audit/skill/mukul975__building-malware-incident-communication-template.json · Report an issue / request a re-scan
04

Audit history

Every audit this skill has had.

DateSourceVerdictGradeScoreChange
2026-10-076c59587be632CAUTIONB89first audit
05

Questions

What does the Building Malware Incident Communication Template skill do?

817 structured cybersecurity skills for AI agents · Mapped to 6 frameworks: MITRE ATT&CK, NIST CSF 2.0, MITRE ATLAS, D3FEND, NIST AI RMF & MITRE F3 (Fight Fraud) · agentskills.io standard · Works with Claude Code, GitHub Copilot, Codex CLI, Cursor, Gemini CLI & 20+ platforms · 29 security domains ·

Is Building Malware Incident Communication Template safe to install?

With care. The audit graded it B (89/100) and found 3 things worth knowing before you trust this skill, listed below with the exact line each was found on.

What can Building Malware Incident Communication Template access on my machine?

The audit observed that it reaches the network. At least one of those is not mentioned in its own description, which is itself a finding. Secrets in the source: none found.

How current is this page?

The grade is for one exact copy of the source (6c59587be632), read on 2026-10-07. The repository is watched, and a new audit runs when it changes — this is the first audit.

Advertisement