1. Prerequisites
- List required access, permissions, or tools needed to perform the task.
2. Step-by-Step Instructions
- Confirm Task Assignment
- Verify assignment and review relevant incident details.
- Notify Stakeholders
- Inform the incident commander and relevant team members that you are starting the task.
- Access Target System/Resource
- Log in or connect to the affected system, application, or resource as required.
- Document Current State
- Record relevant system or application details (e.g., hostname, IP, user sessions, running processes).
- Preserve Evidence (if applicable)
- Collect and preserve logs, memory, or other volatile data as per evidence handling procedures.
- Execute Task Steps
- Perform the specific technical actions required (e.g., isolate system, collect logs, reset credentials). List each sub-step as needed.
- Verify Task Completion
- Confirm that the intended outcome has been achieved (e.g., system is isolated, logs are collected).
- Update Incident Documentation
- Log all actions taken, including timestamps, commands used, and observations.
- Escalate if Issues Arise
- If you encounter errors or cannot complete the task, escalate to the incident commander or appropriate contact.
- Hand Off or Notify Next Responsible Party
- Inform the next team member or analyst that the task is complete and ready for further action.
3. Post-Action
- Ensure all steps are documented in the incident record or ticket.
- Participate in post-incident review if required.
This template provides a clear, repeatable structure for any IR technical task and can be customised for specific scenarios as needed.
Contributor
Firstname Lastname
GitHub: https://github.com/account
Contributed to the Arcana Incident Response Documentation Framework.
