Incident Response.
Playbook Ready.
Structured containment, eradication, and recovery workflows — built for analysts running active incident response. H3AD-IR brings playbook-driven IR methodology to the platform.
LIVE
root@h3ad-ir:~$status
H3AD-IR — live · 1 tool deployed
root@h3ad-ir:~$ls tools/
PHISHBOOK
phishing incident response playbook
root@h3ad-ir:~$
TOOLS
PHISHBOOK
LIVE
Phishing Incident Playbook
End-to-end phishing IR reference: decision trees, enrichment tools, L1/L2/L3 escalation criteria, and KQL/SPL/XQL query templates across 9 investigation phases.
OPEN PHISHBOOK ↗