Open source incident response playbooks, runbooks, and response plans. The full seven-phase NIST incident response flow for the most common attack patterns.
The Incident Response Playbook Designer is here to help teams prepare for and handle incidents without worrying about missing a critical step.
Each playbook walks the incident response team through all seven phases of the NIST incident response process: Prepare, Detect, Analyze, Contain, Eradicate, Recover, and Post-Incident Handling.
The Playbook Policy Engine is open source. It was built and maintained by the IRC community since 2017 and continues to evolve. New playbooks and refinements come from member submissions, reviewed by the Editorial Committee.
Pick the attack category that matches the incident you are responding to (or planning for). Each playbook is structured as a step by step procedure. Most teams use them in three ways:
The whole point of open source playbooks is community improvement. If you spot something missing, weak, or out of date, submit a refinement. If you have an entirely new playbook to contribute, email it to the team and the Editorial Committee will review it for inclusion.
Check out the pre-defined playbooks derived from standard IR policies and industry best practices. Each follows the same seven-phase NIST flow, from Prepare through Post-Incident Handling, tailored to the attack pattern.
Malware is running rampant on the network.
Open the playbook →Someone is trying to take advantage of users.
Open the playbook →Data is being extracted by external or internal parties.
Open the playbook →A virus is running rampant on the network.
Open the playbook →System performance or availability is compromised.
Open the playbook →User gains access to network illegally.
Open the playbook →User or system credentials have been compromised.
Open the playbook →Unauthorized root access has been detected.
Open the playbook →Abuse of permissions and tools of the network.
Open the playbook →It is time to share your playbook with your team or your industry peers. Share them, review them, discuss them, use them to help you automate your response.
Suggestions, feedback and other questions? Email hello@incidentresponse.com.
Community calls coming up, new resources published, and what we're seeing across the membership.
One email a month. Unsubscribe any time. Read our privacy notice.