What is the whole response, not just the first hour?

IR playbooks

Full-lifecycle response plans: triggers, roles, containment decisions, eradication, recovery and the review afterwards. The first-hour playbooks tell you what to do now; these are what you adapt into your own runbook before anything happens.

PlaybookCONSTRUCTED

Business email compromise response plan: the money first, then the mailbox

Two responses that have to run at once. One is a race with a bank transfer measured in hours. The other is evicting an operator who is still reading the mailbox, and who survives a password reset unless you remove what they left behind.

T1566.002T1078.004T1114.003T1564.008T1098.003+2
v1.0checked 2026-09-21cloud
PlaybookCONSTRUCTED

Insider threat response plan: evidence, proportion and the employee who may have done nothing

The response where the usual instincts are wrong. Speed matters less than lawfulness, the suspect is a colleague with rights, and half of these turn out to be misunderstanding. A plan for investigating quietly, preserving what you would need, and being able to stand behind how you did it.

T1078T1213T1567.002T1052.001T1048+3
v1.0checked 2026-09-21windows · macos · cloud
PlaybookCONSTRUCTED

Ransomware response plan: from the first renamed file to the review

The whole response rather than the first hour of it: who decides what, how to contain without destroying the evidence you will need, what has to be true before you restore, and the notifications whose clocks started before you noticed.

T1486T1490T1489T1021.002T1078+1
v1.0checked 2026-09-21windows · linux · cloud

Other shelves: Detection rules · Artifact references · Analyst tools