AI Prompts Cheatsheet for Incident Response

📱 Mobile Security Tips

Sarah Chen — iOS Security Specialist

Why AI Changes the Game for Incident Response

Incident response (IR) is crucial for managing and addressing security incidents. Using AI tools like ChatGPT can dramatically enhance the efficiency of IR processes. From generating quick responses to drafting incident reports, AI can act as a force multiplier for security teams.

Before You Start: How to Set Context Properly

For effective results, it’s essential to set context when deploying AI for incident response tasks. Start by clearly defining the incident type, the specific information needed, and relevant classifications (e.g., severity level, affected systems). This context will enable the AI to generate more relevant and accurate outputs.

Core Prompts Cheatsheet

Generate a summary of the last incident report for a phishing attack involving employee credentials. Include key action items.

What it does: Summarizes past incidents and highlights action items.

When to use it: When reviewing previous phishing incidents to inform current responses.

How to customize: Replace “phishing” with other types of attacks, or specify more details like date range.

Draft a communications plan for stakeholders about a ransomware attack impacting the finance department.

What it does: Generates a communication plan outlining key messages to inform stakeholders.

When to use it: During or immediately after an incident to ensure all stakeholders are informed.

How to customize: Change “ransomware” to another type of incident; specify the department affected.

Can you compile a list of potential indicators of compromise (IOCs) related to the recent APT attack reported in the news?

What it does: Retrieves known IOCs related to recent Advanced Persistent Threats.

When to use it: In the threat intelligence gathering phase.

How to customize: Specify the APT group or timeframe of the attack.

Help me construct a checklist for initial containment strategies for a data breach.

What it does: Provides a step-by-step checklist for containment actions.

When to use it: When responding to a discovered data breach.

How to customize: Tailor the checklist based on specific data types or breach scenarios.

What are best practices for documentation during an incident response?

What it does: Outlines best practices for maintaining thorough documentation during an IR.

When to use it: When creating or refining IR processes.

How to customize: Focus on specific documentation types relevant to your organization.

Generate a report template for incidents categorized as low severity.

What it does: Offers a template structure for reporting low-severity incidents.

When to use it: When logging minor incidents for record-keeping.

How to customize: Adjust the severity classification or add more sections relevant to your context.

Weak vs Strong Prompt Examples

❌ Weak: Tell me about incidents
âś… Strong: Summarize the key incidents that occurred in our environment in the last month, focusing on severity and impact.
❌ Weak: What should we do in a breach?
âś… Strong: Outline an actionable incident response plan tailored to a data breach involving sensitive customer information, including notification protocols.

Advanced Prompt Techniques

To maximize your results, consider employing the following techniques:

  • Role Prompting: Ask the AI to assume a persona—like that of a SOC analyst or CISO—to tailor its outputs.
  • Chain of Thought: Break down complex prompts into a series of logical steps to guide the AI through reasoning effectively.
  • Few-Shot Examples: Provide examples of desired outputs within the prompt to clarify the expected format and details.
  • Output Formatting: Specify the desired output format (e.g., bullet points, tables) to enhance readability.

Claude vs ChatGPT: Which Works Better For This

Both Claude and ChatGPT have strengths, but for incident response:

  • ChatGPT: Often excels in generating structured outputs and can format complex information well.
  • Claude: Tends to offer clearer explanations and may excel in providing nuanced, contextual responses.

Experiment with both to see which aligns better with your needs.

Tips for Getting Consistent Results

  • Context Setting: Always set the context to frame the query appropriately.
  • Specificity: The more specific you are with your requests, the better the responses.
  • Iterative Refinement: Use follow-up prompts to clarify or expand upon previous outputs.

Quick Reference: All Prompts in One Place

  1. Generate a summary of the last incident report for a phishing attack involving employee credentials.
  2. Draft a communications plan for stakeholders about a ransomware attack impacting the finance department.
  3. Compile a list of potential indicators of compromise (IOCs) related to the recent APT attack.
  4. Construct a checklist for initial containment strategies for a data breach.
  5. Discuss best practices for documentation during an incident response.
  6. Generate a report template for low severity incidents.