NIST SP 800-61 Rev. 3
Current incident-response recommendations aligned to the six functions of NIST CSF 2.0. Rev. 3 supersedes Rev. 2.
RESPONDER LIBRARY
Frameworks, tools, field notes, and reusable artifacts for incident detection and response.
Last reviewed: July 17, 2026
Use these to structure governance, preparation, execution, and post-incident improvement.
Current incident-response recommendations aligned to the six functions of NIST CSF 2.0. Rev. 3 supersedes Rev. 2.
Risk outcomes across Govern, Identify, Protect, Detect, Respond, and Recover.
Adversary tactics and techniques for investigation scoping, detection coverage, and purple-team validation.
Layer-based mapping for observed behavior, detection coverage, and response priorities.
Behavioral analytic ideas mapped to ATT&CK techniques and relevant data sources.
Principles and process guidance for managing information-security incidents.
Represent behavior as portable logic, test it against real telemetry, and track coverage.
| Resource | Operational use | Deployment | Access |
|---|---|---|---|
| Sigma | Portable detection rules and backend translation | Repository / pipeline | Open source |
| YARA | File and memory pattern matching | Host / analysis pipeline | Open source |
| KQL | Telemetry hunting, correlation, and analytics | Microsoft security services | Commercial platform |
| Elastic detection rules | Versioned detection logic and unit tests | Elastic Security | Open repository |
| ATT&CK Navigator | Coverage, gap, and incident-behavior mapping | Browser / local deployment | Open source |
Correlate process, persistence, session, credential, and directory activity before isolating assets or disabling identities.
| Resource | Operational use | Deployment | Data-handling note |
|---|---|---|---|
| Microsoft Defender for Endpoint | Endpoint detection, advanced hunting, investigation, and live response | SaaS / endpoint sensor | Tenant-controlled telemetry; validate retention |
| CrowdStrike Falcon | Endpoint detection, investigation, containment, and real-time response | SaaS / endpoint sensor | Cloud telemetry; validate regional and retention requirements |
| Microsoft Entra ID Protection | Risky user, sign-in, and identity investigation | SaaS | Correlate risk events with audit and endpoint evidence |
| Microsoft Defender for Identity | Hybrid identity detection and lateral-movement investigation | SaaS / directory sensors | Preserve directory and authentication logs |
| BloodHound Community Edition | Identity attack-path analysis | Self-hosted | Graph data is highly sensitive; restrict access |
Collect control-plane, identity, workload, packet, and application evidence as a single incident timeline.
Use targeted triage first, then escalate to full acquisition when scope, legal hold, or investigative depth requires it.
| Tool | Operational use | Deployment | Access |
|---|---|---|---|
| Velociraptor | Fleet-scale endpoint triage, artifact collection, and hunting | Self-hosted / endpoint client | Open source |
| KAPE | Targeted Windows triage and artifact processing | Responder workstation | Free |
| FTK Imager | Disk imaging and forensic acquisition | Responder workstation | Free |
| Autopsy / Sleuth Kit | Disk, filesystem, and artifact analysis | Analyst workstation | Open source |
| Volatility 3 | Memory-image analysis | Analyst workstation | Open source |
| X-Ways Forensics | Disk, filesystem, memory, and case analysis | Analyst workstation | Commercial |
Record the source, collector, UTC timestamps, acquisition method, tool version, cryptographic hash, storage location, and every transfer. Avoid changing system state unless the response decision justifies it and the action is recorded.
Separate initial classification, dynamic behavior, and reverse engineering. Never treat a single scanner verdict as conclusive.
Before submitting a file, URL, packet capture, document, or indicator to a public analysis service, confirm the organizationβs data-handling policy. Public or community submissions may become accessible to vendors, researchers, or other service users. Use private analysis, contractual controls, or an isolated internal sandbox for sensitive material.
Use intelligence to add context and prioritize decisionsβnot as a substitute for evidence from the affected environment.
Plain Markdown artifacts designed for quick adaptation during preparation or an active incident.
Prioritize hands-on investigation, evidence interpretation, reporting, and decision-making over credential collecting.
Notification duties depend on jurisdiction, sector, contract, data type, and materiality. Engage counsel and privacy leadership early; do not infer reporting clocks from a generic checklist.
A mix of durable references and continuously updated field research.