Eight chapters covering the full incident response lifecycle from NIST 800-61 and SANS PICERL through preparation, scoping and evidence, containment strategy, eradication, recovery, post-incident review, and specialized playbooks for ransomware, BEC, insider threat, and cloud incidents. Built for analysts moving from SOC-scoped triage into full ownership of an incident from detection to closure.
No chapters match “”.
SOC-scoped incident handling versus full IR ownership, the NIST 800-61 and SANS PICERL frameworks compared, incident classification and severity, and the roles that make up an IR team.
Building an incident response plan, the difference between an IRP and a playbook, IR tooling and the jump bag, and running tabletop exercises.
Scoping an incident once it becomes full IR, evidence collection and chain of custody, building an incident timeline, and common analysis pitfalls.
Short-term versus long-term containment, the factors that drive containment decisions, containment techniques by incident type, and the contain-versus-watch dilemma.
Root cause versus symptom removal, common eradication actions, verifying eradication actually worked, and deciding when to rebuild instead of clean.
Phased restoration priorities, validation before returning systems to production, heightened post-recovery monitoring, and communicating recovery status.
Running a blameless lessons-learned meeting, writing an after-action report, the IR metrics that matter, and legal and regulatory breach notification obligations.
How incident response adapts for ransomware, business email compromise, insider threats, and cloud environments, tying the full PICERL lifecycle together.
WHAT YOU SHOULD KNOW
WHAT YOU WILL KNOW AFTER
H3AD-SEC tools that pair directly with this module's content.
A 7-step phishing investigation tracker with a live IOC aggregator, a working model of the case tracking and disposition discipline this module's chapters assume.
Multi-source IOC analysis across VirusTotal, Shodan, OTX, and AbuseIPDB, useful for the IOC pivoting and scoping work covered in Chapter 3.
Parses 18 forensic artifact types, a direct fit for the evidence collection and timeline reconstruction work covered in Chapter 3.
Email header and risk analysis across 18 risk codes, a direct fit for the mailbox forensics work in Chapter 8's BEC response section.