Vendor Runbooks
Vendor Runbooks
Per-product triage for the tools in your stack — what an alert from each vendor means and what to do about it.
Per-product triage for the tools in your stack — what an alert from each vendor means and what to do about it.
1Password Business
Run 1Password Business admin work: vault and group structure, sharing discipline, the Emergency Kit, recovery groups, and suspend-then-recover offboarding.
Abnormal Security
Triage Abnormal Security email cases: read ATO and BEC behavioral signals, treat account takeover as an identity incident, finish auto-remediation gaps.
Acronis Cyber Protect
Handle Acronis Cyber Protect alerts: separate a backup failure from an Active Protection anti-ransomware detection and run the matching triage discipline.
APC UPS Alerts
Work APC UPS alerts: on-battery events, low runtime, self-test failure, or replace-battery indicators. Separate utility issues from UPS hardware faults.
Arctic Wolf MDR
Work Arctic Wolf MDR escalations: pick up where their SOC investigation ended and split response authority between Arctic Wolf and the MSP correctly.
Auvik Network Monitoring
Triage Auvik network alerts: separate device-down, interface-down, and config-change events, and use the topology map to spot cascades early.
Axcient Backup Alerts
Triage Axcient x360Recover alerts: distinguish appliance vs Direct-to-Cloud failure families, verify retention, and state the last recoverable point.
Bitdefender GravityZone
Triage Bitdefender GravityZone alerts: identify the detection layer (AV, ATC, HyperDetect, EDR) and use Risk Analytics, quarantine, and rollback safely.
Bitwarden Business
Run Bitwarden Teams/Enterprise admin work: organization and collection structure, group-based sharing, account recovery, and offboarding vault handover.
Blackpoint SOC Response
Work Blackpoint MDR SOC calls: confirm what analysts contained (host isolation, account disable), finish the response, and merge companion ticket storms.
Cork Protection Posture
Handle Cork cyber-warranty posture signals: identify the required control that slipped and restore it to compliance before warranty coverage lapses.
Cove Data Protection Alerts
Work N-able Cove Data Protection backup tickets: classify the failure family, verify recoverability, and keep archive and retention sessions straight.
CrowdStrike Falcon Alerts
Triage CrowdStrike Falcon detections: parse detection anatomy, decide when Network Contain is warranted, and spot mass endpoint failures as vendor-side.
Datto BCDR Verification
Work Datto BCDR alerts: screenshot-verification failures, local vs cloud sync lag, virtualization tests. Separate backup-ran from backup-boots and verify.
Defender M365 Alerts
Triage Microsoft Defender and Entra alerts: Safe Links or Safe Attachments detonation, suspicious inbox rules, risky sign-in. Correlate to the incident.
Defender Quarantine Ops
Review Microsoft 365 Defender quarantine items and release requests using Defender portal paths, verdict types, and disciplined release mechanics.
DNS Filtering Alerts
Handle DNS-filter block events from Cisco Umbrella, DNSFilter, and similar tools: separate security blocks from category blocks, keep bypass discipline.
Duo MFA Anomalies
Work Duo MFA events: fraudulent pushes, push-fatigue patterns, device re-enrollment, bypass codes. Verify identity and time-box every bypass grant.
ESET PROTECT
Triage ESET PROTECT detections by engine, interpret LiveGuard sandbox verdicts, and recognize when a protection-disabled alert is really a policy conflict.
Huntress EDR Incident
Work Huntress EDR incident reports: foothold, persistence, or active endpoint threats. Read what Huntress isolated, finish remediation, and verify closure.
Huntress ITDR Alerts
Work Huntress ITDR identity reports: unwanted access, rogue apps, mail-rule anomalies. Verify with the user and drive the remediation-approval flow closed.
IRONSCALES Phishing
Work IRONSCALES phishing incidents and user banner reports: mailbox-level detection, automated remediation, and correct model-training feedback.
Kaseya Dark Web Monitoring
Work Kaseya Dark Web ID compromise alerts: parse alert anatomy (source, date, data classes) and run the age-and-notify lifecycle with a no-crack policy.
Keeper Password Manager
Run Keeper Security admin work: vault and shared-folder structure, role-enforced sharing, break-glass access, and offboarding via Account Transfer.
KnowBe4 Awareness & PhishER
Run a KnowBe4 program: awareness training, phishing simulations, and triage user reports through PhishER and the Phish Alert Button without collisions.
LastPass Migration
Run a LastPass migration-away: export, import to a new vault, rotate every secret, decommission the account, and handle the breach-history talk with facts.
M365 SaaS Backup
Work M365 and Google Workspace SaaS backup tickets: point-in-time restores, license and seat reconciliation, and job failures with authorization checks.
Mimecast Email Gateway
Work Mimecast gateway events: held-message release requests, URL Protect click alerts, and impersonation-protect hits. Treat allowed clicks as incidents.
NinjaOne Alert Types
Classify NinjaOne condition and threshold alerts (offline, resource, service, patch, hardware, security) and route each class with a deep-link handoff.
Proofpoint Email Security
Work Proofpoint email security events: TAP click alerts, attachment-sandbox verdicts, quarantine-digest release requests, and VAP-driven priority triage.
SaaS Alerts MDR
Triage SaaS Alerts events in M365 and Google tenants: login anomalies, mail-rule creation, file-activity spikes, privilege changes as identity-plane EDR.
ScreenConnect Access
Troubleshoot ScreenConnect / ConnectWise Control access: unattended-agent health, session connectivity, and console handoff for the technician on duty.
Security Vendor Generic
Handle security alerts from any vendor without a dedicated runbook: extract alert anatomy, map severity to desk tiers, build a vendor escalation package.
SentinelOne Ranger
Work SentinelOne Ranger network-discovery findings: read the rogue or unmanaged-device signal and drive to identify-then-manage without blind action.
SentinelOne Threat Verdict
Triage SentinelOne threat detections: read static vs behavioral engine verdicts, direct kill, quarantine, rollback, and hold on exclusion requests.
Sophos Endpoint Alerts
Triage Sophos Central endpoint alerts: read health status and cleanup result, handle tamper protection correctly, and verify cleanup before closing.
Synology NAS Alerts
Work Synology NAS alerts: degraded RAID or storage pool, disk-health warnings, full volumes, DSM updates. Treat a degraded array as near data loss.
TeamViewer Access
Troubleshoot TeamViewer remote access: host and agent health, unattended access, session connectivity, and the commercial-use-detected flag on handoff.
ThreatDown Malwarebytes
Triage ThreatDown (Malwarebytes) detections by class — malware, PUP, PUM, exploit — and run the remediation-verification pass the remediated status skips.
ThreatLocker Allowlisting
Work ThreatLocker approval and elevation requests: triage daily allowlisting safely, keep Learning vs Secured mode straight, protect zero-trust posture.
Todyl Platform
Route Todyl alerts by plane: SASE network, endpoint EDR, or identity and SIEM detection. Each plane needs a different runbook from the same platform.
Trend Micro Worry-Free
Triage Trend Micro Worry-Free alerts by engine (signature, ML, behavior, web reputation) and know when a client is on Apex Central or Vision One instead.
Veeam Job Failures
Diagnose Veeam backup job failures: classify by taxonomy (VSS, credentials, repository, network), apply retry discipline, and state the last restore point.
WatchGuard Firewall Alerts
Triage WatchGuard events: Firebox offline in WatchGuard Cloud, AuthPoint MFA push and token trouble, and mobile VPN authentication failures on the desk.
Webroot Legacy AV
Work Webroot or other legacy signature-AV detections with thin telemetry, and frame the modern-EDR migration conversation on facts, not fear.
Was this page helpful?
⌘I