Recognize and declare
Treat these signals as an incident when they cross an authorization, confidentiality, integrity, availability, or safety boundary.
- Confirmed encryption, ransom note, or destructive file changes
- EDR or identity telemetry shows lateral movement with privileged access
- Backup, hypervisor, identity, or security tooling is targeted
Preserve the evidence
Collect authoritative records before destructive cleanup whenever operationally safe. Record source, collector, UTC time, integrity hash, access, and retention decision.
- EDR process trees, volatile connections, memory and host timelines
- Identity, VPN, remote access, authentication, and privilege-change logs
- File server, hypervisor, backup, cloud, firewall, DNS, and proxy telemetry
- Ransom notes, samples, hashes, commands, accounts, IPs, domains, and UTC timestamps
IR-01 · FIRST 15 MINUTES
Reduce immediate uncertainty
- Declare a critical incident; assign command, operations, forensics, recovery, and communications owners.
- Isolate confirmed hosts and block known command-and-control paths while preserving management visibility.
- Protect identity, hypervisor, backup, and security-management planes; pause destructive automation.
- Snapshot volatile evidence and identify the earliest affected identity, host, and execution event.
- Determine whether encryption, exfiltration, or destructive actions remain active.
Contain → eradicate → recover
PHASE / 01Contain
- Disable compromised identities and remote-access paths using scoped revocation first.
- Segment affected networks and restrict east-west protocols without cutting off forensic collection.
- Make backup repositories immutable or offline and verify attackers cannot reach recovery credentials.
PHASE / 02Eradicate
- Rebuild compromised systems from trusted media; do not rely on cleaning unknown persistence.
- Remove unauthorized identities, tools, scheduled tasks, services, policies, and remote-management changes.
- Rotate affected credentials from a known-clean administrative workstation.
PHASE / 03Recover
- Restore identity and security controls before business workloads.
- Validate backups, recovery points, dependencies, monitoring, and business-owner acceptance.
- Reconnect in stages with heightened detection and a tested isolation rollback.
Decision gates
Record the owner, evidence, uncertainty, operational impact, and rollback condition at every transition.
Containment gate
Active encryption and attacker access are stopped; evidence collection and recovery infrastructure remain available.
Eradication gate
Initial access, privilege escalation, lateral movement, and persistence are explained and removed.
Recovery gate
Trusted restores pass security and business validation, monitoring is active, and rollback owners are named.
Rollback safeguard: define the last known-good state, measurable failure signals, accountable decision owner, and fastest safe return path before restoring service.
AUTHORSHIP & REVIEW
How to trust and adapt this guide
- Author & accountable editor
- Leandro Rocha
- Version
- 1.0
- Published / reviewed
- 18 August 2026
- Review status
- Maintainer-reviewed; independent peer review is not claimed.
Reference basis
- NIST SP 800-61 Rev. 3 incident-response guidance
- CISA ransomware response guidance
- MITRE ATT&CK Enterprise techniques
Assumptions
- The organization has authorized incident leadership, protected communications, and access to relevant telemetry.
- Actions are adapted to business impact, legal obligations, architecture, and available evidence before execution.
Limitations
- This field guide is not a substitute for organization-specific legal, privacy, safety, regulatory, or business-continuity advice.
- Vendor interfaces and log availability vary by product, plan, region, configuration, and retention period.