Major Security Incident Management
Purpose: Provide a command-and-coordination playbook for Sev 0 or major security incidents. Use this playbook to establish incident command, run the war room, coordinate multiple technical playbooks, manage executive/legal communications, prioritise recovery, and track decisions until the incident is downgraded or…
Employee Verification During a Security Incident
Purpose: Define how responders verify an employee's identity before taking high-impact security actions such as account recovery, device replacement, access restoration, or sensitive incident discussions. Scope: Applies when a user's identity must be confirmed during an incident. Verification may use live video over…
Major Incident War Room Management
Purpose: Define how to run the command channel, meeting cadence, action tracker, decision log, and status updates for a major security incident. Scope: Applies to Sev 0 or major security incidents requiring cross-functional coordination, executive visibility, multiple technical workstreams, or extended response across…
Ransomware Incident Response
Purpose: This playbook outlines the end-to-end response process for ransomware incidents, including containment, scoping, eradication, recovery, and post-incident hardening. Scope: Applies to all ransomware-related incidents across the organisation, including: - Endpoint ransomware - Server encryption events -…
Endpoint Malware Infection
Purpose: To describe the incident response steps for a malware compromise on corporate workstations, servers, or cloud hosts. Scope: Applies to all endpoint malware incidents across the organisation, including: - Commodity malware infections - Initial access malware (loaders, droppers) - Remote access trojans (RATs) -…
Account Takeover
Purpose: This playbook outlines the response process for account takeover (ATO) incidents - compromised workforce, service, SaaS, and cloud identities; session hijacking; credential abuse; MFA bypass; and unauthorised account activity. The objective is to revoke attacker access, determine what the identity accessed,…
Cloud Compromise
Purpose: To describe the incident response steps for a compromise of cloud infrastructure - covering analysis & triage, containment, eradication, recovery, and post-incident activities. The objective is to evict the attacker from the cloud environment, determine what cloud resources, data, and identities they reached,…
Web Application Attack
Purpose: Provide a clear response workflow for suspected or confirmed web application attacks, including exploitation, API abuse, broken access control, web shells, application-layer denial of service, data exposure, and application tampering. Scope: Applies to internet-facing and internal web applications, APIs,…
Privilege Escalation
Purpose: This playbook defines the response workflow for suspected or confirmed privilege escalation, including unauthorised elevation from standard user to administrator, abuse of privileged roles, local privilege escalation on endpoints, directory privilege escalation, cloud IAM escalation, service account abuse,…
Lateral Movement
Purpose: This playbook defines the response workflow for suspected or confirmed lateral movement. It is used to identify how an attacker moved between systems, accounts, applications, cloud resources, or network segments; stop additional movement; preserve evidence; and coordinate recovery. Scope: Applies to lateral…
Suspicious Execution
Purpose: This playbook defines the response workflow for suspicious process, command-line, script, binary, or interpreter execution. It helps responders validate whether activity is authorised, malicious, or part of a broader incident such as malware, privilege escalation, lateral movement, account takeover, cloud…
Third-Party Compromise
Purpose: Provide a structured response for suspected or confirmed third-party compromise. Use this playbook to validate the report, assess exposure, restrict risky access, identify secondary impact, and restore trusted access safely. Scope: Applies to compromised vendors, suppliers, MSPs, SaaS providers, cloud…
Distributed Denial of Service (DDoS)
Purpose: Provide a structured response for suspected or confirmed DDoS attacks. Use this playbook to validate service impact, analyse traffic, activate mitigation, restore availability, and assess whether the DDoS is masking broader attacker activity. Scope: Applies to volumetric, protocol, application-layer, DNS,…
Lost & Stolen Device
Purpose: Provide a structured response for lost, misplaced, or stolen organisational devices. Use this playbook to validate the report, assess device and data exposure, contain access, coordinate device recovery or replacement, and restore the user safely. Scope: Applies to corporate-owned or managed laptops,…
Active Exploitation
Purpose: Provide a structured response for confirmed vulnerability exploitation. Use this playbook to validate exploitation evidence, scope affected assets, preserve evidence, contain attacker access, eradicate persistence, and coordinate recovery. Scope: Applies when exploitation is confirmed against organisational…
Vulnerability Response
Purpose: Provide a structured response for critical or high-risk vulnerabilities where remediation, containment, and validation are required. Use this playbook to validate the vulnerability, identify exposed assets, reduce risk, coordinate patching or configuration changes, and confirm remediation. Scope: Applies to…
Zero-Day Response
Purpose: Provide a structured response for zero-day vulnerabilities where no vendor patch or durable fix is available. Use this playbook to validate exposure, reduce exploitability, monitor for exploitation, coordinate vendor communications, and transition to remediation when a fix becomes available. Scope: Applies to…
Session & Token Revocation
1. Prerequisites Authentication telemetry Session inventory OAuth telemetry Identity provider logs Access to identity provider Access to OAuth management platform Access to SIEM Access to SaaS administration consoles 2. Step-by-Step Instructions Common Failure Modes - Resetting passwords without revoking sessions -…
Process Tree Analysis
1. Prerequisites EDR telemetry access Process creation logs Command-line arguments data File execution telemetry User activity logs EDR platform access SIEM platform access Process analysis tools 2. Step-by-Step Instructions 1. Identify Initial Execution Process - Determine: - Initial executable - Launch source - User…
Malware Persistence Mechanism Hunt
1. Prerequisites EDR telemetry Registry activity Scheduled task logs Service creation logs Startup artefacts Access to EDR platform Access to Autoruns Access to PowerShell Access to registry analysis tools Access to SIEM 2. Step-by-Step Instructions 1. Review Startup Persistence - Check: - Startup folders - Registry…
Malware Analysis
1. Prerequisites Malware samples File hashes EDR telemetry Sandbox results Process execution telemetry Network telemetry Access to sandbox environment Access to reverse engineering tools Access to threat intelligence platforms Access to EDR platform Access to memory analysis tools 2. Step-by-Step Instructions Common…
Outbound Traffic Analysis
1. Prerequisites Alert, incident, or investigation involving suspicious outbound network activity (e.g. C2 / beaconing, data exfiltration, unauthorised transfer, post-exploitation comms, reverse shell) Access to firewall logs Access to proxy logs Access to DNS logs Access to NetFlow or network telemetry Access to EDR…
Data Staging Investigation
1. Prerequisites Suspected or confirmed data exfiltration incident Access to EDR telemetry Access to endpoint forensic tooling Access to file system artifacts Access to SIEM Access to operating system event logs Access to cloud workload telemetry (if applicable) Hostnames, usernames, and assets identified during…
Sensitive Data Impact Assessment
1. Prerequisites Suspected or confirmed data exfiltration incident Completion of: - Outbound Traffic Analysis - Data Staging Investigation - Cloud Storage & SaaS Review (if applicable) Access to data classification standards Access to data inventory or asset inventory Access to data owners and business stakeholders…

