Open reference library
Playbooks for the work in front of you.
Follow a practical path from first alert or hunt question to evidence, a decision and a handoff. 26 curated playbooks are readable without an account. Your ticks stay in this browser; you can copy the checklist or download JSON.
26 playbooks
SOC
Day-to-day triage and analyst handoffs
- 8 steps · SOC analysts and shift leadsFirst-pass alert triageTurn an alert into an evidence-based disposition and a usable handoff.Open playbook
- 8 steps · SOC analysts and email security teamsReported phishing messageReview a reported message, find other recipients and route the response.Open playbook
- 12 steps · SOC analysts, email security and incident respondersAdvanced phishing and campaign triagePreserve message evidence, scope campaign delivery, trace user impact and verify approved remediation.Open playbook
- 8 steps · SOC analysts and identity teamsSuspicious sign-in investigationCorrelate authentication, session and account-change evidence.Open playbook
Detection engineering
Review rules, data, translations and tuning
- 8 steps · Detection engineers and SOC reviewersDetection rule peer reviewReview behavior, telemetry, logic, evidence and analyst handoff.Open playbook
- 8 steps · Detection and platform engineersMissing telemetry investigationFind whether collection, parsing, mapping or query scope caused a gap.Open playbook
- 8 steps · Engineers using Splunk, Sentinel, Elastic or WazuhSigma translation validationReview a supported SIEM preview against local mappings and test cases.Open playbook
- 8 steps · Detection engineers and SOC leadsDetection tuning and regressionReduce known noise while protecting the behavior the rule should see.Open playbook
Threat hunting
Turn hypotheses into evidence and detections
- 8 steps · Threat hunters and detection engineersBuild a threat-hunting hypothesisTurn a behavior question into observable tests and bounded data needs.Open playbook
- 8 steps · Threat hunters and SOC analystsPivot from one suspicious eventExpand from a lead across entity, time and behavior without losing scope.Open playbook
- 8 steps · Threat hunters, detection engineers and SOC leadsPromote a hunt into a detectionMove from an exploratory query to a testable rule and analyst response.Open playbook
Alert response
Investigate what a detection says happened
- 20 steps · Credential Access respondersCredential theftSomething tried to read, guess or forge credentials. Assume what it touched is now known to the adversary.Open playbook
- 10 steps · Execution / Initial Access respondersUnexpected executionCode ran somewhere code does not normally run — a document, a signed utility, an interpreter.Open playbook
- 9 steps · Persistence respondersPersistence establishedSomething arranged to run again later. The immediate risk is low; the risk of missing it is not.Open playbook
- 9 steps · Privilege Escalation respondersPrivilege escalationAn attempt to gain rights the account did not have, or to run inside a process that already had them.Open playbook
- 9 steps · Defense Evasion respondersDefence evasionSomething tried to hide, disable logging, or look like software it is not. Treat other alerts as unreliable from this point.Open playbook
- 8 steps · Discovery respondersDiscovery and enumerationSomeone was mapping the estate. On its own it is weak evidence; alongside anything else it is a timeline anchor.Open playbook
- 9 steps · Lateral Movement respondersLateral movementActivity reaching from one host to another. The question is which direction, and what the source already had.Open playbook
- 10 steps · Command and Control respondersCommand and controlA channel out. Containment competes with evidence collection here more sharply than anywhere else.Open playbook
- 9 steps · Collection / Exfiltration respondersCollection and exfiltrationData being gathered or moved. This is where a security incident becomes a disclosure obligation.Open playbook
- 12 steps · Impact respondersDestructive impactSomething moved to destroy, encrypt or disable. The only family where speed genuinely beats certainty.Open playbook
Incident scenarios
Follow an incident across response families
- 11 steps · Incident responders and SOC leadsCritical incident: standing up the responseNot a technical playbook. The one you run alongside it when an incident outgrows the people on it.Open playbook
- 11 steps · Incident responders and SOC leadsRansomware, end to endAccess, then credentials, then movement, then encryption. You are almost never at the start of it.Open playbook
- 10 steps · Incident responders and SOC leadsBusiness email compromiseNo malware, no endpoint. A valid login, a mail rule, and an invoice that goes to the wrong account.Open playbook
- 9 steps · Incident responders and SOC leadsInsider data theftA legitimate user, legitimate access, and the wrong intent. Almost nothing here is technically anomalous.Open playbook
- 10 steps · Incident responders and SOC leadsInternet-facing server compromiseAn edge application exploited, a web shell dropped, and the server used as a foothold inward.Open playbook
These are general guides. Match investigation, escalation and disruptive actions to your organisation’s approved processes and available telemetry. Sources and scope are listed on each playbook.