Incident Response Playbooks
Standardized, step-by-step response workflows. Pick one to work an incident; each ties into the platform's analysis and takedown tools.
Sanctions Screening & Escalation
7 steps · Normalize the subject (entity/individual/vessel + aliases + country)…
Human Trafficking Triage
8 steps · Preserve the referral and any digital artifacts (accounts, ads, numbers)…
Disinformation / Influence Op Response
7 steps · Capture the narrative, first-seen date, and amplifying accounts…
NetFlow Anomaly Investigation
7 steps · Ingest the relevant flow window (NetFlow/IPFIX CSV) into NetFlow Analysis…
Phishing Response
9 steps · Confirm the report and preserve the original email (headers + body)…
Ransomware Response
9 steps · Isolate affected hosts from the network immediately…
APT / Targeted Intrusion
9 steps · Scope the intrusion; identify entry vector and dwell time…
Business Email Compromise
8 steps · Verify the fraudulent request out-of-band (phone the real party)…
Crypto Fraud / Scam
7 steps · Collect wallet addresses, scam domains, and social handles…
Malicious Infrastructure Takedown
7 steps · Select target infrastructure (ASN / hosting / nameserver)…
Malware Triage & Analysis
8 steps · Acquire the sample safely; record MD5/SHA1/SHA256…
C2 Infrastructure Hunting
7 steps · Pull known-C2 IoCs (ThreatFox, Bambenek, OTX, Feodo)…
Data Breach Response
8 steps · Confirm and scope: what data, which systems, timeframe…
DDoS Mitigation
6 steps · Characterize the attack: volumetric / protocol / application-layer…
Insider Threat Investigation
6 steps · Establish scope and legal/HR authorization before collecting…
🤖 AI Copilot
⚡ AI Skills
🔍 Lookup & Enrich
📚 Docs & Reports
💡 Recommendations
- Explore related tools below
- Automate recurring work via cron