Response playbook
najjab_playbookRetrieves the incident response playbook for a chosen incident type: how it appears, first-hour steps, containment, eradication, recovery, evidence to keep, and follow-up.
Instructions
The playbook for an incident type: how it shows up, the first hour, containment, eradication, recovery, the evidence to keep and what to do after.
Input Schema
| Name | Required | Description | Default |
|---|---|---|---|
| lang | No | Language for the answer: en or ar. | en |
| incident_type | Yes | ransomware, bec (business email compromise), data-breach or cloud-key (exposed cloud access keys). | |
| response_format | No | markdown for reading, json for further processing. | markdown |