← Operations Web Function

Preserve Web Incident Skill

CANDIDATE CANDIDATE NEW BOUNDED TASK · Operations Web Function 0.1.0. Capture minimally necessary, reproducible web incident evidence and chain of custody before remediation changes or destroys it. Use for suspected compromise, cloaking, injected spam, rogue redirects, reinfection, unauthorized access, destructive repair requests, or any incident where volatile public responses, logs, files, users, jobs, or host state may be needed to establish cause and persistence.

Canonical owner: operations-web-function:preserve-web-incident · Task registration: TASK_LIBRARY_REGISTRATION_PENDING

Broader definitive hub · Exact Task Library page: TASK_LIBRARY_REGISTRATION_PENDING

Download the complete plugin · Source skill SHA-256: cbdf702d7411d66e25bbcfb593e526425387ed154a1b4d33f628488b209ceb90

Candidate source: dennisyu/blitzmetrics-skills · commit: PENDING_MERGE · path: skills/preserve-web-incident/SKILL.md

Preserve first when changing the system could erase the answer. This skill is evidence collection, not cleanup.

Preservation plan

  1. Confirm authorization, target, time window, privacy class, and evidence destination.
  2. Record the source finding and exact reproduction inputs: URL, identity, vantage, headers requested, timestamps, tool version/hash, and control result.
  3. Capture the smallest sufficient public response set, headers, hashes, screenshots when layout matters, DNS/TLS facts, and search-index evidence.
  4. When authorized, collect read-only internal corroboration: users, dependencies, must-use extensions, scheduled tasks, relevant file metadata and hashes, logs, database indicators, and host state.
  5. Hash each artifact and record collector, collection time, source, redaction class, and storage reference.
  6. Separate untouched originals from redacted working copies.
  7. State missing evidence and collection failures as UNKNOWN.
  8. Produce a chain-of-custody receipt and a safe triage summary.

Boundaries

Completion

Preservation is complete when a second authorized operator can reproduce the finding or verify why it can no longer be reproduced, artifact hashes and custody are recorded, unknowns are explicit, and remediation can proceed without relying on memory.

Return to $triage-web-incidents for containment and route any change through $change-web-production.


This is a generated candidate implementation page, not automatically a definitive article or accepted Task Library task. It delegates to the named canonical owner until reviewed registration and merge receipts exist.