Incident Response Playbooks¶
What I do once an incident is confirmed. Each playbook follows the standard template.
- Phishing: malicious email delivered to users
- Compromised Account / BEC: Microsoft 365 and Entra ID account takeover and business email compromise
- Ransomware: encryption or confirmed ransomware precursors
- Endpoint Malware: malicious code on a workstation or server
- Exploited Edge Device: VPN, firewall, and other internet-facing appliances
- Active Directory Privileged Compromise: Domain Admin compromise, DCSync, Kerberos attacks
For the lifecycle behind these playbooks, see Incident Response.