First-hour playbooks

Written to be read while something is happening rather than studied beforehand. Short, imperative, and ordered by what expires rather than by what is interesting.

why these six

Chosen against what is actually happening rather than what is interesting to write. Business email compromise is the most common incident type reported, and MFA was defeated in essentially every case where it was deployed, which is why the cloud playbook spends its length on consent grants and session tokens rather than on passwords.

Edge devices and VPNs went from a small share of exploitation-driven breaches to roughly a fifth of them in a single year, and remote access is the entry point behind the large majority of ransomware intrusions where anyone could establish one. That is the fastest growing route in and the one most estates have least tooling for, so it has a playbook of its own.

Figures from the current Verizon DBIR and from vendor incident reporting. They move; the shape of the response does not.

read this bit now, not later

These are a starting point for your own runbooks, not a substitute for them. Your estate, your authority to contain a host, and your legal obligations are yours, and a playbook that does not know them cannot be followed literally.

The first is free in full so you can judge the rest by it. What they are good for is the shape: what to collect before it rolls, what order to do it in, and the mistake that gets made under pressure. Take them, change them, put your own escalation names in them.

01

Ransomware, suspected or confirmed

Files renamed or unreadable, a ransom note, or backup deletion commands seen.

The window between the destruction sequence and encryption is minutes. If you are reading this before encryption has finished, containment is worth more than evidence.

6 steps · 2 time-critical · links to 4 artifact entries

02

Cloud account compromisePro

Impossible travel, an unrecognised inbox rule, or a reported invoice-fraud attempt.

The visible artifact is rarely the mechanism. Removing it and resetting the password feels like a response and frequently is not one.

5 steps · 2 time-critical · links to 1 artifact entries

03

Suspicious execution on an endpointPro

An EDR alert, an unexplained process, or a user reporting something odd.

The most common alert and the one where an hour of careful work most often prevents a week of incident. Most of these are not incidents, and the goal is to establish which.

5 steps · 1 time-critical · links to 6 artifact entries

04

Suspected data theft by an insiderPro

A resignation with unusual file access, a DLP alert, or an unexplained large transfer.

The evidence in these cases is more often about intent than about volume, and it is the case type most likely to end up in front of somebody who will test how it was collected.

4 steps · 1 time-critical · links to 5 artifact entries

05

Edge appliance or VPN compromisePro

A vendor advisory for a device you run at the perimeter, unexplained admin sessions on it, or an internal alert whose earliest source is the VPN range.

The fastest-growing intrusion route there is, and the one your normal tooling covers least. Edge devices went from a small share of exploitation-driven breaches to roughly a fifth of them in a single year, and remote access is the entry point behind the large majority of ransomware intrusions where anyone could establish one.

6 steps · 2 time-critical · links to 3 artifact entries

06

Web shell on a public-facing serverPro

An unfamiliar file in a web root, a web server process spawning a shell, or outbound traffic from a machine that should only ever receive it.

A web shell is a foothold that looks like ordinary web traffic. The detection is usually a file or a process ancestry that makes no sense, and the investigation is mostly about how long it has been there.

5 steps · 2 time-critical · links to 4 artifact entries