Security
Security
Phishing, account takeover, quarantine, dark-web exposure, and the response runbooks that follow an incident.
Phishing, account takeover, quarantine, dark-web exposure, and the response runbooks that follow an incident.
Account Takeover Runbook
Respond to a confirmed account takeover: disable sign-in, revoke sessions, reset MFA, sweep inbox rules and OAuth consents, and notify users.
Breached Credential Response
Handle exposed user credentials: notify the user, drive password rotation across reused sites, and verify MFA is enabled before standing down.
Business Email Compromise Recovery
Recover from confirmed BEC: kill sessions and tokens, sweep mail rules and forwarding, notify downstream victims, and trace the fraudulent funds.
Compromised Account Containment
Rapid containment checklist for a compromised account: block sign-in, revoke sessions, reset password, sweep MFA and inbox rules, timestamp steps.
Credential Stuffing Response
Investigate password spraying and credential stuffing patterns: scope the attack across tenants, lock down accounts, and rotate the ones that fell.
Cyber Risk Posture Review
Review a client's security posture using the cyber risk dashboard, identity data, open detections, and incident history, ranking the top risks.
Dark Web Alert Lifecycle
Work dark-web and credential-exposure alerts: age stale exposures, document closure notes, and notify affected users with rotation guidance.
Defensive Writing Standard
Language standard for security writing: use when drafting client notifications, incident updates, postmortems, and alert closures to avoid overstatement.
DLP Alert Triage
Triage a DLP alert: separate business-process false positives from real data exfiltration signals, investigating with respect for employee privacy.
DMARC SPF Failure Triage
Diagnose SPF, DKIM, and DMARC email authentication failures: distinguish real spoofing attempts from sender misconfiguration and explain to the client.
Domain Expiry Alert Lifecycle
Handle registrar expiry and renewal notices safely: verify the sender is the real registrar, confirm the expiry date, and route to the renewal owner.
EDR Detection Runbook
Work an EDR malware or suspicious-process alert: pull RMM device context, check EDR containment, confirm with the user, then escalate or close.
Email Header Analysis
Parse raw email headers for a spoofing verdict: analyze authentication results, the received path, and spoof indicators with explicit confidence.
Global Admin Audit
Audit a client tenant's global administrator accounts and recent admin-role changes, flagging unexpected admins, missing MFA, and unauthorized grants.
Identity MFA Health Check
Review a client's identity hygiene — MFA coverage, privileged accounts, and stale accounts — and return ranked findings with remediation recommendations.
Impossible Travel Runbook
Investigate an impossible-travel or atypical-location sign-in alert: check VPN and travel, verify with the user by phone, and contain on confirmed ATO.
Inbox Rule Alert Runbook
An alert fired for a suspicious inbox rule created on a user's mailbox — judge legitimacy, inventory all rules, and remove plus rotate if malicious.
Insider Risk Basics
Handle insider-risk signals like data staging, sabotage, or access abuse: preserve evidence quietly, escalate to client HR, and keep it confidential.
Lost or Stolen Device Response
Respond to a lost or stolen laptop or phone: decide lock or wipe, assess exposed data and access, and drive carrier or police steps with approval gates.
MDR Client Onboarding
Onboard a client to a new MDR or SOC service: scope assets, wire alert routing into the desk, record escalation contacts, and set noise expectations.
MFA Fatigue Attack Response
Respond to MFA push bombing and fatigue attacks: treat the password as known, contain the account, and enforce number-matching so approval spam fails.
Monthly Security Report
Produce a client's monthly security digest: incident and alert counts, notable events, posture trend, and recommendations for client or internal review.
New User Created Alert
Investigate an unexpected user or admin account creation in a client tenant: check for an authorizing ticket and contain if no one can claim it.
OAuth Consent Grant Abuse
Remove a malicious or over-privileged OAuth consent grant from a client tenant: identify the grant, revoke it, and tighten tenant consent policy.
Phishing Simulation Program
Plan a client phishing-awareness simulation: scope, cadence, lure difficulty, a no-shame reporting culture, and desk triage that doesn't collide.
Phishing Triage
Triage a reported phishing email without touching the payload: check blast radius, contain if malicious, and reply to the reporter with a verdict.
Quarantine Release Request
Handle a quarantined email release request: verify the requester, assess why the filter caught it, and recommend release or refusal with reasoning.
Ransomware Response
Respond to suspected or confirmed ransomware: isolate hosts, verify backups before touching them, engage IR and insurance, and sequence recovery.
Security Alert Response
Work an inbound security alert ticket: extract the facts, route to the right client, tier severity, and contain or close with documented reasoning.
Security Incident Postmortem
Build a security incident postmortem: executive summary, timeline, impact, root cause, and action items drawn from ticket evidence in defensible language.
Security Noise Tuning
Reduce recurring false-positive security alerts: quantify the FP rate, build an evidence pack, and recommend a retune at the source tool.
Security Onboarding New Client
Run a new-client security intake: MFA coverage, admin inventory, backup posture, EDR presence, and produce the day-one risk list before an incident.
Session Token Theft Response
Respond to stolen session cookies or tokens after MFA-passed account abuse: revoke sessions and tokens system-wide, not just the user's password.
SOC Classification Tree
Classify a security ticket down the Incident, Request, and Problem tree and set type, subtype, and item consistently for reporting and routing.
SOC Client Email Pack
Pick the right client-outreach template for a security event (leaked credentials, BEC, inbox rule, lookalike domain) and draft with verified facts only.
SOC Shift Handoff
Hand off open security investigations at shift change: evidence state, containment progress, and watch items so the next shift can act immediately.
Typosquat Domain Alert
Work a typosquat or lookalike domain alert impersonating a client: gather registrar and DNS facts without visiting, gauge capability, draft a warning.
Vendor Fraud BEC Alert
Respond to a BEC or payment-fraud attempt (fake invoice, banking-change request, exec impersonation): freeze payments and run callback verification.
Vulnerability Report Triage
Triage a CVE, vendor advisory, or researcher disclosure: assess severity vs exploitability, check affected assets, and plan patch or mitigation steps.
Wire Fraud Verification Protocol
Callback verification for any payment change request: banking updates, new wire instructions, or payroll redirects — verify out-of-band, no exceptions.
Zero-Day Emergency Response
Coordinate an emergency response to an actively exploited zero-day: count each client's exposure, apply mitigations, and communicate the same night.
Was this page helpful?
⌘I