Playbooks¶
These are the procedures I follow when something needs a response. The rest of this toolkit is reference material (event IDs, artifacts, tool usage); the playbooks are how I put it to work, and they link back to the reference pages instead of repeating them.
Types¶
- Incident Response: what I do once an incident is confirmed, from triage through recovery
- Alert Triage: short runbooks for deciding quickly whether a single alert is real
- Threat Hunting: hypothesis-driven searches for activity that did not trigger an alert
- Operations: recurring security work that keeps the defenses healthy
How the Playbooks Are Written¶
- Queries are written in KQL (Microsoft Sentinel and Defender XDR advanced hunting) because that is where identity and email evidence usually lives. The logic carries over to other platforms; for Splunk, see my SPL repo.
- Table and column names follow the Sentinel and Defender XDR schemas. Adjust them if your data arrives through a different connector.
- Time windows and thresholds in the queries are starting points. Tune them to the environment.
Incident Response Playbook Template¶
Every incident response playbook follows the same structure:
- Scope and triggers: what starts the playbook
- Severity: how I decide between low, medium, high, and critical
- ATT&CK mapping: the techniques usually involved
- Data sources: the logs and tools I need
- Flow: a decision diagram of the main path
- Triage, Containment, Eradication, Recovery: numbered steps with the decision points called out
- Queries: KQL for scoping and hunting
- Communication: who I notify and when
- Close-out: evidence to retain, lessons learned, and detections to add