OPERATIONAL PLAYBOOKS

Execute with safeguards

Every action needs evidence, authority, an impact assessment, a rollback path, and a way to prove it worked.

Last reviewed: July 17, 2026Adapt commands and authority before use
BEFORE EXECUTION

Use a common action contract

These playbooks are decision support, not authorization. Replace generic roles, platforms, time targets, and escalation paths with tested local procedures.

TriggerEvidence and confidence required to act.
AuthorityApprover, executor, and affected owner.
SafeguardBusiness, safety, evidence, and adversary tradeoffs.
ValidationSuccess signal, rollback threshold, and owner.
Do not execute disruptive containment mechanically. Confirm critical service, safety, identity, backup, virtualization, automation, and management-path dependencies. When delay creates greater harm, record the emergency authority and validate impact immediately afterward.
PLAYBOOK 01

Ransomware and destructive activity

Triggers: high-confidence encryption, recovery-inhibition commands, ransom artifacts, destructive changes, extortion evidence, or coordinated endpoint alerts. Track the earliest known affected asset or identity and confidence; do not assume the true initial compromise is known.

0–15 minutes

  1. Activate incident command and the protected channel.
  2. Preserve original alerts, ransom artifacts, EDR lineage, identity events, and short-retention logs.
  3. Identify active encryption, privileged sessions, management planes, backup systems, hypervisors, and safety constraints.
  4. Isolate actively destructive endpoints or workloads when authorized; verify isolation.
  5. Protect clean administrative access and prevent affected identities from reaching control planes.

15–60 minutes

  1. Scope lateral movement, remote administration, credential access, exfiltration, and data repositories.
  2. Protect backup control planes and validate offline or immutable recovery copies without connecting them to affected trust zones.
  3. Restrict malicious network paths, identities, infrastructure, hashes, and behaviors with expiration and rollback.
  4. Engage legal, insurer, specialist response, and business owners according to thresholds.
  5. Set restoration priority from business dependencies—not device count.

Architecture blast radius

Systems to assess beyond encrypted endpoints
Trust areaEvidenceDecision
Identity and privileged accessSessions, roles, credentials, tokens, MFA, service principalsRestrict, revoke, rotate, or preserve for controlled observation
Management planeRMM, software deployment, virtualization, cloud and directory auditProtect or suspend compromised automation and admin paths
Backup and recoveryAdministrative activity, deletion, retention, immutability, restore testsIsolate control plane and choose a trusted recovery point
Network and egressSMB/RDP/admin flows, DNS, proxy, VPN, firewall, transfer volumeSegment propagation and exfiltration paths
Data and business servicesRepository access, exports, application transactions, dependenciesPrioritize containment, disclosure assessment, and restoration

Extortion or payment decision

Do not treat executive approval as the only gate. Engage qualified legal counsel, sanctions/compliance review, cyber insurer, law enforcement, and experienced negotiation or response specialists. Preserve communications and decisions. Payment does not guarantee decryption, deletion, non-disclosure, or future safety.

Recovery exit criteria

  • Initial access and persistence addressed with stated confidence.
  • Privileged credentials, tokens, keys, certificates, and affected integrations rotated.
  • Recovery environment and data validated from trusted evidence.
  • Restored systems pass technical and business transaction tests.
  • Enhanced detections cover observed behavior and monitoring owners are assigned.

Download the ransomware containment decision matrix

PLAYBOOK 02

Suspected data exposure or exfiltration

Triggers: anomalous data access, bulk export, public exposure, unauthorized sharing, third-party notice, extortion claim, or validated data-loss alert.

Establish evidence

  • Repository, dataset, record type, owner, sensitivity, jurisdiction, and contractual context
  • Identity, application, token, source, destination, method, time window, and volume
  • Access versus export versus confirmed receipt by an unauthorized party
  • Logging gaps, retention limits, encryption context, and confidence

Contain deliberately

  • Remove public or unauthorized access while preserving configuration evidence
  • Revoke affected sessions, grants, keys, links, or integrations
  • Restrict exfiltration paths and monitor alternate destinations
  • Preserve provider, SaaS, proxy, DLP, identity, and data-plane records
Notification clocks are not generic. Legal and privacy teams must determine duties from jurisdiction, sector, contract, data type, affected individuals, materiality, and confirmed facts. Do not publish speculative record counts or attribution.

Validation

  • Unauthorized access path is closed and tested.
  • Related identities, applications, tokens, repositories, and sharing paths are scoped.
  • Exposure assessment distinguishes known access, likely acquisition, and uncertainty.
  • Preservation, notification, customer, partner, and regulatory decisions are recorded.
PLAYBOOK 03

Phishing and malicious messaging

Triggers: user report, email-security alert, credential-harvesting page, malicious attachment, suspicious OAuth consent, or post-delivery identity activity.

PreserveMessage, headers, URLs, attachments, delivery and click data.
ScopeRecipients, forwards, clicks, submissions, execution, consent.
ContainQuarantine, block, revoke, isolate with safeguards.
InvestigateIdentity, endpoint, mailbox, SaaS and data activity.
RecoverRemove persistence and restore trusted access.
ImproveTune controls and test the observed technique.

Responder actions

  • Analyze content in an isolated environment; do not browse or upload sensitive material to public services without approval.
  • Search by message identifiers, sender infrastructure, URLs, attachment hashes, subject variants, and campaign timing.
  • Quarantine delivered messages and validate removal across mailboxes and collaboration platforms.
  • For credential or token exposure, revoke sessions and refresh tokens; review MFA methods, OAuth grants, mailbox rules, forwarding, delegates, applications, roles, and related endpoint evidence.
  • For attachment execution, isolate affected endpoints when justified and scope process lineage, persistence, credentials, and network activity.
PLAYBOOK 04

Identity or session compromise

Triggers: validated risky sign-in, unexpected session, MFA change, token replay, consent grant, privilege change, mailbox persistence, impossible-travel signal with corroborating evidence, or user report.

Identity containment gate

Before disabling an identity, identify service dependencies, break-glass requirements, active business processes, and alternate attacker persistence. Emergency restriction may be necessary, but password reset alone is not containment.

Investigate

  • Sign-ins, devices, ASN, user agent, authentication method, MFA, risk, session, and token activity
  • Roles, groups, delegation, consent, application registration, keys, certificates, and service principals
  • Mailbox rules, forwarding, delegates, sent mail, file access, sharing, and data exports
  • Endpoint evidence before and after suspicious authentication

Contain and recover

  • Block or restrict identity according to authority and dependency risk
  • Revoke sessions and refresh tokens; rotate exposed credentials and secrets
  • Remove unauthorized MFA methods, OAuth grants, applications, rules, delegates, roles, and persistence
  • Re-register strong authentication through a verified process
  • Validate the user, device, access, and business function before restoration

Download the identity investigation worksheet

PLAYBOOK 05

Insider-risk investigation

Triggers: anomalous access or export, policy alert, privileged misuse, unauthorized sharing, sabotage indication, credible report, or departure-related risk. An alert is not proof of intent.

Coordinate before collection or confrontation. Legal, privacy, HR, labor relations, and physical-security requirements vary. Apply need-to-know access, preserve objectivity, minimize unnecessary personal data, and avoid alerting the subject when doing so could compromise evidence or safety.
  1. Define the allegation, authorized scope, evidence sources, custodians, and investigative authority.
  2. Preserve access, identity, endpoint, email, collaboration, print, removable-media, cloud, SaaS, and physical-access evidence as legally permitted.
  3. Compare activity to role, approved work, access history, business context, and alternative explanations.
  4. Separate policy violation, negligent action, compromised identity, and intentional misuse hypotheses.
  5. If containment is approved, coordinate timing across digital access, badges, devices, shared secrets, customer systems, and business continuity.
  6. Record findings, confidence, evidentiary limitations, decisions, and access to the case.
PLAYBOOK 06

Malware outbreak

Triggers: correlated endpoint detections, repeated malicious process lineage, command-and-control behavior, persistence across systems, or multiple affected assets. If encryption or destructive behavior is present, use the ransomware playbook.

Classify and scope

  • Execution chain, signer, hashes, capabilities, persistence, privilege, credential access, and configuration
  • Delivery vector, earliest known activity, affected users/assets, network destinations, and propagation
  • Public-service submission restrictions and internal sandbox requirements
  • Related behavior beyond static indicators

Contain and eradicate

  • Isolate active infections with service-owner safeguards
  • Block validated infrastructure, artifacts, and behavior with expiry and rollback
  • Remove persistence or rebuild from trusted images based on assurance needs
  • Patch or close the delivery path and rotate exposed trust material
  • Hunt for alternate variants, infrastructure, identities, and execution paths

Validation

  • No related execution, persistence, command and control, or propagation during the monitoring window.
  • EDR and logging health restored on every affected asset class.
  • Initial access path tested as closed.
  • Business owners validate restored applications and dependencies.
  • New or updated detections pass representative tests.
SPECIALIZED PLAYBOOKS

AI and software supply-chain incidents

AI-IR-01 — AI / LLM incident

Control unsafe agency, preserve ephemeral AI state, scope identities and downstream actions, isolate poisoned knowledge, and recover through staged rollback.

Open AI-IR-01

IR-07 — Repository compromise

Preserve Git and audit evidence, contain compromised identities and automation, validate dependencies, and rebuild artifacts from trusted source.

Open repository-compromise response