Quick reference for incident response — the lifecycle phases, triage questions, and evidence collection commands.
IR LifecycleForensicsDetectionPlaybooks
IR Lifecycle: NIST vs SANS
| NIST SP 800-61 |
SANS PICERL |
| Preparation | Preparation |
| Detection & Analysis | Identification |
| Containment, Eradication & Recovery | Containment |
| Containment, Eradication & Recovery | Eradication |
| Containment, Eradication & Recovery | Recovery |
| Post-Incident Activity | Lessons Learned |
Triage Checklist
Core Questions
- What? True or false positive; what kind of activity.
- When? First observed time (UTC); is it ongoing.
- Scope? Hosts, accounts, and data affected.
- Severity? Business impact and urgency.
- Who/where? Owner, location, criticality of assets.
- Evidence? What must be preserved before acting.
Severity Classification
| Level |
Example |
Response |
| SEV-1 | Ransomware, breach, domain compromise | All-hands, exec/legal now |
| SEV-2 | Host malware w/ C2, privileged misuse | Contain within hours |
| SEV-3 | Contained commodity malware | Business hours |
| SEV-4 | Policy violation, blocked scan | Log & monitor |
Order of Volatility
- CPU registers & cache
- RAM, process table, ARP/routing, kernel stats
- Temp filesystems & swap
- Disk (persistent storage)
- Remote logs & monitoring data
- Physical config & topology
- Archival media / backups
Live-Response Commands
| Task |
Linux |
Windows |
| Processes | ps auxf | Get-Process / tasklist |
| Connections | ss -tunap | netstat -ano |
| Logins | last -F / lastb | Event ID 4624/4625 |
| Logs | journalctl --since | Get-WinEvent |
| Persistence | crontab -l, systemd units | schtasks, Autoruns |
| Open files | lsof -p PID | handle.exe |
Evidence Integrity
# Hash on acquisition
sha256sum evidence.dd > evidence.dd.sha256
# Verify later
sha256sum -c evidence.dd.sha256
# Image a disk (source -> file)
dd if=/dev/sdb of=disk.dd bs=4M conv=noerror,sync status=progress
# Memory capture then hash
avml mem.lime && sha256sum mem.lime
IOC Types
| Type |
Example |
| Hash | SHA-256 of malware |
| Network | C2 IP, domain, URL |
| Host | File path, registry key, mutex |
| Account | Rogue user, impossible-travel login |
| TTP | ATT&CK technique (e.g. T1059) |
Playbook Quick Steps
Phishing
- Preserve original email + full headers.
- Identify recipients and who clicked/entered creds.
- Purge the message org-wide; block sender & URL.
- Reset exposed credentials; revoke sessions.
Ransomware
- Isolate affected hosts immediately.
- Preserve a sample; identify the variant.
- Locate patient zero & entry vector.
- Restore from clean, offline backups; don't rush to pay.
Account Compromise
- Disable/lock account; revoke tokens & sessions.
- Reset password and re-enroll MFA.
- Review inbox rules and OAuth app grants.
- Hunt for lateral movement from the account.
Notification / Breach Timelines
| Regime |
Deadline |
| GDPR (EU) | 72h to supervisory authority |
| HIPAA (US) | Without undue delay, max 60 days |
| SEC (US public co.) | 4 business days after materiality |
| PCI DSS | Notify acquirer/brands immediately |
Useful Tools
| Tool |
Use |
| Volatility 3 | Memory forensics & analysis |
| Autopsy / Sleuth Kit | Disk forensics & file recovery |
| Velociraptor | Endpoint hunting & live response at scale |
| Wireshark | Packet capture & network analysis |
| SIEM (Splunk/ELK/Sentinel) | Log correlation, detection, timelines |
| KAPE | Rapid triage artifact collection (Windows) |