Arcana

Incident-response documentation

Playbooks, runbooks, SOPs and templates from the Arcana framework, published as a single read-only feed.

June 202624 documents
PlaybookJun 8
PB-019

Major Security Incident Management

Purpose: Provide a command-and-coordination playbook for Sev 0 or major security incidents. Use this playbook to establish incident command, run the war room, coordinate multiple technical playbooks, manage executive/legal communications, prioritise recovery, and track decisions until the incident is downgraded or…

Open document
SOPJun 8
SOP-006

Employee Verification During a Security Incident

Purpose: Define how responders verify an employee's identity before taking high-impact security actions such as account recovery, device replacement, access restoration, or sensitive incident discussions. Scope: Applies when a user's identity must be confirmed during an incident. Verification may use live video over…

Open document
SOPJun 8
SOP-007

Major Incident War Room Management

Purpose: Define how to run the command channel, meeting cadence, action tracker, decision log, and status updates for a major security incident. Scope: Applies to Sev 0 or major security incidents requiring cross-functional coordination, executive visibility, multiple technical workstreams, or extended response across…

Open document
PlaybookJun 8
PB-002

Ransomware Incident Response

Purpose: This playbook outlines the end-to-end response process for ransomware incidents, including containment, scoping, eradication, recovery, and post-incident hardening. Scope: Applies to all ransomware-related incidents across the organisation, including: - Endpoint ransomware - Server encryption events -…

Open document
PlaybookJun 8
PB-003

Endpoint Malware Infection

Purpose: To describe the incident response steps for a malware compromise on corporate workstations, servers, or cloud hosts. Scope: Applies to all endpoint malware incidents across the organisation, including: - Commodity malware infections - Initial access malware (loaders, droppers) - Remote access trojans (RATs) -…

Open document
PlaybookJun 8
PB-004

Account Takeover

Purpose: This playbook outlines the response process for account takeover (ATO) incidents - compromised workforce, service, SaaS, and cloud identities; session hijacking; credential abuse; MFA bypass; and unauthorised account activity. The objective is to revoke attacker access, determine what the identity accessed,…

Open document
PlaybookJun 8
PB-007

Cloud Compromise

Purpose: To describe the incident response steps for a compromise of cloud infrastructure - covering analysis & triage, containment, eradication, recovery, and post-incident activities. The objective is to evict the attacker from the cloud environment, determine what cloud resources, data, and identities they reached,…

Open document
PlaybookJun 8
PB-008

Web Application Attack

Purpose: Provide a clear response workflow for suspected or confirmed web application attacks, including exploitation, API abuse, broken access control, web shells, application-layer denial of service, data exposure, and application tampering. Scope: Applies to internet-facing and internal web applications, APIs,…

Open document
PlaybookJun 8
PB-009

Privilege Escalation

Purpose: This playbook defines the response workflow for suspected or confirmed privilege escalation, including unauthorised elevation from standard user to administrator, abuse of privileged roles, local privilege escalation on endpoints, directory privilege escalation, cloud IAM escalation, service account abuse,…

Open document
PlaybookJun 8
PB-010

Lateral Movement

Purpose: This playbook defines the response workflow for suspected or confirmed lateral movement. It is used to identify how an attacker moved between systems, accounts, applications, cloud resources, or network segments; stop additional movement; preserve evidence; and coordinate recovery. Scope: Applies to lateral…

Open document
PlaybookJun 8
PB-011

Suspicious Execution

Purpose: This playbook defines the response workflow for suspicious process, command-line, script, binary, or interpreter execution. It helps responders validate whether activity is authorised, malicious, or part of a broader incident such as malware, privilege escalation, lateral movement, account takeover, cloud…

Open document
PlaybookJun 8
PB-012

Third-Party Compromise

Purpose: Provide a structured response for suspected or confirmed third-party compromise. Use this playbook to validate the report, assess exposure, restrict risky access, identify secondary impact, and restore trusted access safely. Scope: Applies to compromised vendors, suppliers, MSPs, SaaS providers, cloud…

Open document
PlaybookJun 8
PB-013

Distributed Denial of Service (DDoS)

Purpose: Provide a structured response for suspected or confirmed DDoS attacks. Use this playbook to validate service impact, analyse traffic, activate mitigation, restore availability, and assess whether the DDoS is masking broader attacker activity. Scope: Applies to volumetric, protocol, application-layer, DNS,…

Open document
PlaybookJun 8
PB-014

Lost & Stolen Device

Purpose: Provide a structured response for lost, misplaced, or stolen organisational devices. Use this playbook to validate the report, assess device and data exposure, contain access, coordinate device recovery or replacement, and restore the user safely. Scope: Applies to corporate-owned or managed laptops,…

Open document
PlaybookJun 8
PB-015

Active Exploitation

Purpose: Provide a structured response for confirmed vulnerability exploitation. Use this playbook to validate exploitation evidence, scope affected assets, preserve evidence, contain attacker access, eradicate persistence, and coordinate recovery. Scope: Applies when exploitation is confirmed against organisational…

Open document
PlaybookJun 8
PB-017

Vulnerability Response

Purpose: Provide a structured response for critical or high-risk vulnerabilities where remediation, containment, and validation are required. Use this playbook to validate the vulnerability, identify exposed assets, reduce risk, coordinate patching or configuration changes, and confirm remediation. Scope: Applies to…

Open document
PlaybookJun 8
PB-018

Zero-Day Response

Purpose: Provide a structured response for zero-day vulnerabilities where no vendor patch or durable fix is available. Use this playbook to validate exposure, reduce exploitability, monitor for exploitation, coordinate vendor communications, and transition to remediation when a fix becomes available. Scope: Applies to…

Open document
Runbook · ContainJun 8
RB-CONTAIN-005

Session & Token Revocation

1. Prerequisites Authentication telemetry Session inventory OAuth telemetry Identity provider logs Access to identity provider Access to OAuth management platform Access to SIEM Access to SaaS administration consoles 2. Step-by-Step Instructions Common Failure Modes - Resetting passwords without revoking sessions -…

Open document
Runbook · AnalysisJun 8
RB-ANALYSIS-006

Process Tree Analysis

1. Prerequisites EDR telemetry access Process creation logs Command-line arguments data File execution telemetry User activity logs EDR platform access SIEM platform access Process analysis tools 2. Step-by-Step Instructions 1. Identify Initial Execution Process - Determine: - Initial executable - Launch source - User…

Open document
Runbook · AnalysisJun 8
RB-ANALYSIS-014

Malware Persistence Mechanism Hunt

1. Prerequisites EDR telemetry Registry activity Scheduled task logs Service creation logs Startup artefacts Access to EDR platform Access to Autoruns Access to PowerShell Access to registry analysis tools Access to SIEM 2. Step-by-Step Instructions 1. Review Startup Persistence - Check: - Startup folders - Registry…

Open document
Runbook · AnalysisJun 8
RB-ANALYSIS-015

Malware Analysis

1. Prerequisites Malware samples File hashes EDR telemetry Sandbox results Process execution telemetry Network telemetry Access to sandbox environment Access to reverse engineering tools Access to threat intelligence platforms Access to EDR platform Access to memory analysis tools 2. Step-by-Step Instructions Common…

Open document
Runbook · AnalysisJun 8
RB-ANALYSIS-018

Outbound Traffic Analysis

1. Prerequisites Alert, incident, or investigation involving suspicious outbound network activity (e.g. C2 / beaconing, data exfiltration, unauthorised transfer, post-exploitation comms, reverse shell) Access to firewall logs Access to proxy logs Access to DNS logs Access to NetFlow or network telemetry Access to EDR…

Open document
Runbook · AnalysisJun 8
RB-ANALYSIS-019

Data Staging Investigation

1. Prerequisites Suspected or confirmed data exfiltration incident Access to EDR telemetry Access to endpoint forensic tooling Access to file system artifacts Access to SIEM Access to operating system event logs Access to cloud workload telemetry (if applicable) Hostnames, usernames, and assets identified during…

Open document
Runbook · AnalysisJun 8
RB-ANALYSIS-021

Sensitive Data Impact Assessment

1. Prerequisites Suspected or confirmed data exfiltration incident Completion of: - Outbound Traffic Analysis - Data Staging Investigation - Cloud Storage & SaaS Review (if applicable) Access to data classification standards Access to data inventory or asset inventory Access to data owners and business stakeholders…

Open document