Build a step-by-step incident response playbook for a specific attack type, covering detection, containment, eradication, recovery, and lessons learned.
Create a detailed Incident Response (IR) playbook for the following attack scenario:
Attack type:
Environment:
Key systems at risk:
Team structure:
Structure the playbook across the NIST IR phases:
1. Preparation — tools, contacts, and pre-incident requirements
2. Detection & Analysis — how to identify and triage this attack type
3. Containment — short-term and long-term containment steps
4. Eradication — root cause removal procedures
5. Recovery — safe restoration steps and validation checks
6. Post-Incident — lessons learned template and reporting obligations
Include decision trees for key escalation points and flag any legal or regulatory notification triggers.
Ask me up to 3 questions before starting if it would improve the quality of your response.