contentintech

Incident Response Cheatsheet

Quick reference for incident response — the lifecycle phases, triage questions, and evidence collection commands.

IR LifecycleForensicsDetectionPlaybooks
NotesCheatsheet

IR Lifecycle: NIST vs SANS

NIST SP 800-61 SANS PICERL
PreparationPreparation
Detection & AnalysisIdentification
Containment, Eradication & RecoveryContainment
Containment, Eradication & RecoveryEradication
Containment, Eradication & RecoveryRecovery
Post-Incident ActivityLessons Learned

Triage Checklist

Core Questions

  1. What? True or false positive; what kind of activity.
  2. When? First observed time (UTC); is it ongoing.
  3. Scope? Hosts, accounts, and data affected.
  4. Severity? Business impact and urgency.
  5. Who/where? Owner, location, criticality of assets.
  6. Evidence? What must be preserved before acting.

Severity Classification

Level Example Response
SEV-1Ransomware, breach, domain compromiseAll-hands, exec/legal now
SEV-2Host malware w/ C2, privileged misuseContain within hours
SEV-3Contained commodity malwareBusiness hours
SEV-4Policy violation, blocked scanLog & monitor

Order of Volatility

  1. CPU registers & cache
  2. RAM, process table, ARP/routing, kernel stats
  3. Temp filesystems & swap
  4. Disk (persistent storage)
  5. Remote logs & monitoring data
  6. Physical config & topology
  7. Archival media / backups

Live-Response Commands

Task Linux Windows
Processesps auxfGet-Process / tasklist
Connectionsss -tunapnetstat -ano
Loginslast -F / lastbEvent ID 4624/4625
Logsjournalctl --sinceGet-WinEvent
Persistencecrontab -l, systemd unitsschtasks, Autoruns
Open fileslsof -p PIDhandle.exe

Evidence Integrity

# Hash on acquisition
sha256sum evidence.dd > evidence.dd.sha256

# Verify later
sha256sum -c evidence.dd.sha256

# Image a disk (source -> file)
dd if=/dev/sdb of=disk.dd bs=4M conv=noerror,sync status=progress

# Memory capture then hash
avml mem.lime && sha256sum mem.lime

IOC Types

Type Example
HashSHA-256 of malware
NetworkC2 IP, domain, URL
HostFile path, registry key, mutex
AccountRogue user, impossible-travel login
TTPATT&CK technique (e.g. T1059)

Playbook Quick Steps

Phishing

  1. Preserve original email + full headers.
  2. Identify recipients and who clicked/entered creds.
  3. Purge the message org-wide; block sender & URL.
  4. Reset exposed credentials; revoke sessions.

Ransomware

  1. Isolate affected hosts immediately.
  2. Preserve a sample; identify the variant.
  3. Locate patient zero & entry vector.
  4. Restore from clean, offline backups; don't rush to pay.

Account Compromise

  1. Disable/lock account; revoke tokens & sessions.
  2. Reset password and re-enroll MFA.
  3. Review inbox rules and OAuth app grants.
  4. Hunt for lateral movement from the account.

Notification / Breach Timelines

Regime Deadline
GDPR (EU)72h to supervisory authority
HIPAA (US)Without undue delay, max 60 days
SEC (US public co.)4 business days after materiality
PCI DSSNotify acquirer/brands immediately

Useful Tools

Tool Use
Volatility 3Memory forensics & analysis
Autopsy / Sleuth KitDisk forensics & file recovery
VelociraptorEndpoint hunting & live response at scale
WiresharkPacket capture & network analysis
SIEM (Splunk/ELK/Sentinel)Log correlation, detection, timelines
KAPERapid triage artifact collection (Windows)

Section navigation