Playbooks

Incident Response Playbooks

Standardized, step-by-step response workflows. Pick one to work an incident; each ties into the platform's analysis and takedown tools.

Sanctions Screening & Escalation

7 steps · Normalize the subject (entity/individual/vessel + aliases + country)…

Human Trafficking Triage

8 steps · Preserve the referral and any digital artifacts (accounts, ads, numbers)…

Disinformation / Influence Op Response

7 steps · Capture the narrative, first-seen date, and amplifying accounts…

NetFlow Anomaly Investigation

7 steps · Ingest the relevant flow window (NetFlow/IPFIX CSV) into NetFlow Analysis…

Phishing Response

9 steps · Confirm the report and preserve the original email (headers + body)…

Ransomware Response

9 steps · Isolate affected hosts from the network immediately…

APT / Targeted Intrusion

9 steps · Scope the intrusion; identify entry vector and dwell time…

Business Email Compromise

8 steps · Verify the fraudulent request out-of-band (phone the real party)…

Crypto Fraud / Scam

7 steps · Collect wallet addresses, scam domains, and social handles…

Malicious Infrastructure Takedown

7 steps · Select target infrastructure (ASN / hosting / nameserver)…

Malware Triage & Analysis

8 steps · Acquire the sample safely; record MD5/SHA1/SHA256…

C2 Infrastructure Hunting

7 steps · Pull known-C2 IoCs (ThreatFox, Bambenek, OTX, Feodo)…

Data Breach Response

8 steps · Confirm and scope: what data, which systems, timeframe…

DDoS Mitigation

6 steps · Characterize the attack: volumetric / protocol / application-layer…

Insider Threat Investigation

6 steps · Establish scope and legal/HR authorization before collecting…

Workstation · Copilot · AI Skills · Automation · Playbooks · Lookups · Docs · Reports

🤖 AI Copilot

🔍 Lookup & Enrich

💡 Recommendations

⚙ Automation

Cron: 0 * * * * php /home/zaptf0zdggll/public_html/threats/cron.php