ArcanaIncident-response documentationBrowse the feedTemplates
Back to feed
Template
RB-000

<Document Name>

1. Prerequisites

  • List required access, permissions, or tools needed to perform the task.

2. Step-by-Step Instructions

  1. Confirm Task Assignment
    • Verify assignment and review relevant incident details.
  2. Notify Stakeholders
    • Inform the incident commander and relevant team members that you are starting the task.
  3. Access Target System/Resource
    • Log in or connect to the affected system, application, or resource as required.
  4. Document Current State
    • Record relevant system or application details (e.g., hostname, IP, user sessions, running processes).
  5. Preserve Evidence (if applicable)
    • Collect and preserve logs, memory, or other volatile data as per evidence handling procedures.
  6. Execute Task Steps
    • Perform the specific technical actions required (e.g., isolate system, collect logs, reset credentials). List each sub-step as needed.
  7. Verify Task Completion
    • Confirm that the intended outcome has been achieved (e.g., system is isolated, logs are collected).
  8. Update Incident Documentation
    • Log all actions taken, including timestamps, commands used, and observations.
  9. Escalate if Issues Arise
    • If you encounter errors or cannot complete the task, escalate to the incident commander or appropriate contact.
  10. Hand Off or Notify Next Responsible Party
    • Inform the next team member or analyst that the task is complete and ready for further action.

3. Post-Action

  • Ensure all steps are documented in the incident record or ticket.
  • Participate in post-incident review if required.

This template provides a clear, repeatable structure for any IR technical task and can be customised for specific scenarios as needed.


Contributor

Firstname Lastname
GitHub: https://github.com/account

Contributed to the Arcana Incident Response Documentation Framework.