BEFORE EXECUTIONUse a common action contract
These playbooks are decision support, not authorization. Replace generic roles, platforms, time targets, and escalation paths with tested local procedures.
TriggerEvidence and confidence required to act.
AuthorityApprover, executor, and affected owner.
SafeguardBusiness, safety, evidence, and adversary tradeoffs.
ValidationSuccess signal, rollback threshold, and owner.
Do not execute disruptive containment mechanically. Confirm critical service, safety, identity, backup, virtualization, automation, and management-path dependencies. When delay creates greater harm, record the emergency authority and validate impact immediately afterward.
PLAYBOOK 01Ransomware and destructive activity
Triggers: high-confidence encryption, recovery-inhibition commands, ransom artifacts, destructive changes, extortion evidence, or coordinated endpoint alerts. Track the earliest known affected asset or identity and confidence; do not assume the true initial compromise is known.
0–15 minutes
- Activate incident command and the protected channel.
- Preserve original alerts, ransom artifacts, EDR lineage, identity events, and short-retention logs.
- Identify active encryption, privileged sessions, management planes, backup systems, hypervisors, and safety constraints.
- Isolate actively destructive endpoints or workloads when authorized; verify isolation.
- Protect clean administrative access and prevent affected identities from reaching control planes.
15–60 minutes
- Scope lateral movement, remote administration, credential access, exfiltration, and data repositories.
- Protect backup control planes and validate offline or immutable recovery copies without connecting them to affected trust zones.
- Restrict malicious network paths, identities, infrastructure, hashes, and behaviors with expiration and rollback.
- Engage legal, insurer, specialist response, and business owners according to thresholds.
- Set restoration priority from business dependencies—not device count.
Architecture blast radius
Extortion or payment decision
Do not treat executive approval as the only gate. Engage qualified legal counsel, sanctions/compliance review, cyber insurer, law enforcement, and experienced negotiation or response specialists. Preserve communications and decisions. Payment does not guarantee decryption, deletion, non-disclosure, or future safety.
Recovery exit criteria
- Initial access and persistence addressed with stated confidence.
- Privileged credentials, tokens, keys, certificates, and affected integrations rotated.
- Recovery environment and data validated from trusted evidence.
- Restored systems pass technical and business transaction tests.
- Enhanced detections cover observed behavior and monitoring owners are assigned.
Download the ransomware containment decision matrix
PLAYBOOK 02Suspected data exposure or exfiltration
Triggers: anomalous data access, bulk export, public exposure, unauthorized sharing, third-party notice, extortion claim, or validated data-loss alert.
Establish evidence
- Repository, dataset, record type, owner, sensitivity, jurisdiction, and contractual context
- Identity, application, token, source, destination, method, time window, and volume
- Access versus export versus confirmed receipt by an unauthorized party
- Logging gaps, retention limits, encryption context, and confidence
Contain deliberately
- Remove public or unauthorized access while preserving configuration evidence
- Revoke affected sessions, grants, keys, links, or integrations
- Restrict exfiltration paths and monitor alternate destinations
- Preserve provider, SaaS, proxy, DLP, identity, and data-plane records
Notification clocks are not generic. Legal and privacy teams must determine duties from jurisdiction, sector, contract, data type, affected individuals, materiality, and confirmed facts. Do not publish speculative record counts or attribution.
Validation
- Unauthorized access path is closed and tested.
- Related identities, applications, tokens, repositories, and sharing paths are scoped.
- Exposure assessment distinguishes known access, likely acquisition, and uncertainty.
- Preservation, notification, customer, partner, and regulatory decisions are recorded.
PLAYBOOK 03Phishing and malicious messaging
Triggers: user report, email-security alert, credential-harvesting page, malicious attachment, suspicious OAuth consent, or post-delivery identity activity.
PreserveMessage, headers, URLs, attachments, delivery and click data.
ScopeRecipients, forwards, clicks, submissions, execution, consent.
ContainQuarantine, block, revoke, isolate with safeguards.
InvestigateIdentity, endpoint, mailbox, SaaS and data activity.
RecoverRemove persistence and restore trusted access.
ImproveTune controls and test the observed technique.
Responder actions
- Analyze content in an isolated environment; do not browse or upload sensitive material to public services without approval.
- Search by message identifiers, sender infrastructure, URLs, attachment hashes, subject variants, and campaign timing.
- Quarantine delivered messages and validate removal across mailboxes and collaboration platforms.
- For credential or token exposure, revoke sessions and refresh tokens; review MFA methods, OAuth grants, mailbox rules, forwarding, delegates, applications, roles, and related endpoint evidence.
- For attachment execution, isolate affected endpoints when justified and scope process lineage, persistence, credentials, and network activity.
PLAYBOOK 04Identity or session compromise
Triggers: validated risky sign-in, unexpected session, MFA change, token replay, consent grant, privilege change, mailbox persistence, impossible-travel signal with corroborating evidence, or user report.
Identity containment gate
Before disabling an identity, identify service dependencies, break-glass requirements, active business processes, and alternate attacker persistence. Emergency restriction may be necessary, but password reset alone is not containment.
Investigate
- Sign-ins, devices, ASN, user agent, authentication method, MFA, risk, session, and token activity
- Roles, groups, delegation, consent, application registration, keys, certificates, and service principals
- Mailbox rules, forwarding, delegates, sent mail, file access, sharing, and data exports
- Endpoint evidence before and after suspicious authentication
Contain and recover
- Block or restrict identity according to authority and dependency risk
- Revoke sessions and refresh tokens; rotate exposed credentials and secrets
- Remove unauthorized MFA methods, OAuth grants, applications, rules, delegates, roles, and persistence
- Re-register strong authentication through a verified process
- Validate the user, device, access, and business function before restoration
Download the identity investigation worksheet
PLAYBOOK 05Insider-risk investigation
Triggers: anomalous access or export, policy alert, privileged misuse, unauthorized sharing, sabotage indication, credible report, or departure-related risk. An alert is not proof of intent.
Coordinate before collection or confrontation. Legal, privacy, HR, labor relations, and physical-security requirements vary. Apply need-to-know access, preserve objectivity, minimize unnecessary personal data, and avoid alerting the subject when doing so could compromise evidence or safety.
- Define the allegation, authorized scope, evidence sources, custodians, and investigative authority.
- Preserve access, identity, endpoint, email, collaboration, print, removable-media, cloud, SaaS, and physical-access evidence as legally permitted.
- Compare activity to role, approved work, access history, business context, and alternative explanations.
- Separate policy violation, negligent action, compromised identity, and intentional misuse hypotheses.
- If containment is approved, coordinate timing across digital access, badges, devices, shared secrets, customer systems, and business continuity.
- Record findings, confidence, evidentiary limitations, decisions, and access to the case.
PLAYBOOK 06Malware outbreak
Triggers: correlated endpoint detections, repeated malicious process lineage, command-and-control behavior, persistence across systems, or multiple affected assets. If encryption or destructive behavior is present, use the ransomware playbook.
Classify and scope
- Execution chain, signer, hashes, capabilities, persistence, privilege, credential access, and configuration
- Delivery vector, earliest known activity, affected users/assets, network destinations, and propagation
- Public-service submission restrictions and internal sandbox requirements
- Related behavior beyond static indicators
Contain and eradicate
- Isolate active infections with service-owner safeguards
- Block validated infrastructure, artifacts, and behavior with expiry and rollback
- Remove persistence or rebuild from trusted images based on assurance needs
- Patch or close the delivery path and rotate exposed trust material
- Hunt for alternate variants, infrastructure, identities, and execution paths
Validation
- No related execution, persistence, command and control, or propagation during the monitoring window.
- EDR and logging health restored on every affected asset class.
- Initial access path tested as closed.
- Business owners validate restored applications and dependencies.
- New or updated detections pass representative tests.