Skip to main content
Phishing, account takeover, quarantine, dark-web exposure, and the response runbooks that follow an incident.

Account Takeover Runbook

Respond to a confirmed account takeover: disable sign-in, revoke sessions, reset MFA, sweep inbox rules and OAuth consents, and notify users.

Breached Credential Response

Handle exposed user credentials: notify the user, drive password rotation across reused sites, and verify MFA is enabled before standing down.

Business Email Compromise Recovery

Recover from confirmed BEC: kill sessions and tokens, sweep mail rules and forwarding, notify downstream victims, and trace the fraudulent funds.

Compromised Account Containment

Rapid containment checklist for a compromised account: block sign-in, revoke sessions, reset password, sweep MFA and inbox rules, timestamp steps.

Credential Stuffing Response

Investigate password spraying and credential stuffing patterns: scope the attack across tenants, lock down accounts, and rotate the ones that fell.

Cyber Risk Posture Review

Review a client's security posture using the cyber risk dashboard, identity data, open detections, and incident history, ranking the top risks.

Dark Web Alert Lifecycle

Work dark-web and credential-exposure alerts: age stale exposures, document closure notes, and notify affected users with rotation guidance.

Defensive Writing Standard

Language standard for security writing: use when drafting client notifications, incident updates, postmortems, and alert closures to avoid overstatement.

DLP Alert Triage

Triage a DLP alert: separate business-process false positives from real data exfiltration signals, investigating with respect for employee privacy.

DMARC SPF Failure Triage

Diagnose SPF, DKIM, and DMARC email authentication failures: distinguish real spoofing attempts from sender misconfiguration and explain to the client.

Domain Expiry Alert Lifecycle

Handle registrar expiry and renewal notices safely: verify the sender is the real registrar, confirm the expiry date, and route to the renewal owner.

EDR Detection Runbook

Work an EDR malware or suspicious-process alert: pull RMM device context, check EDR containment, confirm with the user, then escalate or close.

Email Header Analysis

Parse raw email headers for a spoofing verdict: analyze authentication results, the received path, and spoof indicators with explicit confidence.

Global Admin Audit

Audit a client tenant's global administrator accounts and recent admin-role changes, flagging unexpected admins, missing MFA, and unauthorized grants.

Identity MFA Health Check

Review a client's identity hygiene — MFA coverage, privileged accounts, and stale accounts — and return ranked findings with remediation recommendations.

Impossible Travel Runbook

Investigate an impossible-travel or atypical-location sign-in alert: check VPN and travel, verify with the user by phone, and contain on confirmed ATO.

Inbox Rule Alert Runbook

An alert fired for a suspicious inbox rule created on a user's mailbox — judge legitimacy, inventory all rules, and remove plus rotate if malicious.

Insider Risk Basics

Handle insider-risk signals like data staging, sabotage, or access abuse: preserve evidence quietly, escalate to client HR, and keep it confidential.

Lost or Stolen Device Response

Respond to a lost or stolen laptop or phone: decide lock or wipe, assess exposed data and access, and drive carrier or police steps with approval gates.

MDR Client Onboarding

Onboard a client to a new MDR or SOC service: scope assets, wire alert routing into the desk, record escalation contacts, and set noise expectations.

MFA Fatigue Attack Response

Respond to MFA push bombing and fatigue attacks: treat the password as known, contain the account, and enforce number-matching so approval spam fails.

Monthly Security Report

Produce a client's monthly security digest: incident and alert counts, notable events, posture trend, and recommendations for client or internal review.

New User Created Alert

Investigate an unexpected user or admin account creation in a client tenant: check for an authorizing ticket and contain if no one can claim it.

OAuth Consent Grant Abuse

Remove a malicious or over-privileged OAuth consent grant from a client tenant: identify the grant, revoke it, and tighten tenant consent policy.

Phishing Simulation Program

Plan a client phishing-awareness simulation: scope, cadence, lure difficulty, a no-shame reporting culture, and desk triage that doesn't collide.

Phishing Triage

Triage a reported phishing email without touching the payload: check blast radius, contain if malicious, and reply to the reporter with a verdict.

Quarantine Release Request

Handle a quarantined email release request: verify the requester, assess why the filter caught it, and recommend release or refusal with reasoning.

Ransomware Response

Respond to suspected or confirmed ransomware: isolate hosts, verify backups before touching them, engage IR and insurance, and sequence recovery.

Security Alert Response

Work an inbound security alert ticket: extract the facts, route to the right client, tier severity, and contain or close with documented reasoning.

Security Incident Postmortem

Build a security incident postmortem: executive summary, timeline, impact, root cause, and action items drawn from ticket evidence in defensible language.

Security Noise Tuning

Reduce recurring false-positive security alerts: quantify the FP rate, build an evidence pack, and recommend a retune at the source tool.

Security Onboarding New Client

Run a new-client security intake: MFA coverage, admin inventory, backup posture, EDR presence, and produce the day-one risk list before an incident.

Session Token Theft Response

Respond to stolen session cookies or tokens after MFA-passed account abuse: revoke sessions and tokens system-wide, not just the user's password.

SOC Classification Tree

Classify a security ticket down the Incident, Request, and Problem tree and set type, subtype, and item consistently for reporting and routing.

SOC Client Email Pack

Pick the right client-outreach template for a security event (leaked credentials, BEC, inbox rule, lookalike domain) and draft with verified facts only.

SOC Shift Handoff

Hand off open security investigations at shift change: evidence state, containment progress, and watch items so the next shift can act immediately.

Typosquat Domain Alert

Work a typosquat or lookalike domain alert impersonating a client: gather registrar and DNS facts without visiting, gauge capability, draft a warning.

Vendor Fraud BEC Alert

Respond to a BEC or payment-fraud attempt (fake invoice, banking-change request, exec impersonation): freeze payments and run callback verification.

Vulnerability Report Triage

Triage a CVE, vendor advisory, or researcher disclosure: assess severity vs exploitability, check affected assets, and plan patch or mitigation steps.

Wire Fraud Verification Protocol

Callback verification for any payment change request: banking updates, new wire instructions, or payroll redirects — verify out-of-band, no exceptions.

Zero-Day Emergency Response

Coordinate an emergency response to an actively exploited zero-day: count each client's exposure, apply mitigations, and communicate the same night.