Skip to content
days until launch · 31 July 2026 ·
Cyber Toolbox
Library

Playbooks & runbooks, written in production.

Incident response, exposure, threat-hunting and team-development playbooks across enterprise IT, cloud, OT/ICS, identity, supply chain, and more — a starting point for almost any scenario. The headline scenarios are free to walk at Community. Browse the whole catalogue below.

160 playbooks · methodology built in

PB-CIRP-101
Enterprise IT

Phishing and Business Email Compromise

Operator response for phishing reports and confirmed Business Email Compromise — twelve sub-scenarios from a single user report through to active wire fraud and tenant-wide account takeover.

FreeRead
PB-CIRP-102
Enterprise IT

Endpoint Malware Detection

Endpoint malware detection — single-host EDR alert through to confirmed multi-host implant. Twelve sub-scenarios; every CIRP that suspects payload execution routes here.

FreeRead
PB-CIRP-103
Enterprise IT

Ransomware

Operator response for human-operated ransomware (HumOR) — from precursor TTPs (VSS deletion, LSASS dumping, recovery tampering) through active encryption to post-impact extortion. Three stage variants (PRE-IMPACT / IN-PROGRESS / POST-IMPACT) drive containment posture.

FreeRead
PB-CIRP-104
Enterprise IT

Account Compromise / MFA Bypass

Operator response for account compromise where multi-factor authentication has been bypassed or defeated — Adversary-in-the-Middle (AiTM) token theft, MFA fatigue, password-spray, and device-code-flow abuse.

FreeRead
PB-CIRP-105
Enterprise IT

Data Exfiltration

Exfil-without-encryption response — quantify what left, where it went, and notify on regulatory clocks.

FreeRead
PB-CIRP-106
Enterprise IT

Insider Threat — Malicious

Confirmed malicious-insider response — coordinated with HR and Legal. Adversarial-employment posture from the start, with evidence discipline for disciplinary, tribunal, or law-enforcement use.

FreeRead
PB-CIRP-107
Enterprise IT

Privileged Account Abuse

Targeted misuse of standing administrative rights — break-glass abuse, service-account abuse, contractor admin misuse. Distinct from generic account takeover.

FreeRead
PB-CIRP-108
Enterprise IT

Lateral Movement Detection

Off-host pivot detection. RDP, SMB, WMI and WinRM lateral patterns — contain the spread before encryption or staging fires.

FreeRead
PB-CIRP-109
Enterprise IT

Destructive Malware / Wiper

Destructive malware / wiper response — non-recoverable by design. Containment is recovery-from-clean-source, not eviction. NotPetya / Olympic Destroyer / WhisperGate class.

FreeRead
PB-CIRP-110
Enterprise IT

Cryptominer Infection

Resource-hijack response for unauthorised cryptocurrency mining on endpoints, servers, containers, or cloud workloads. Light-track variant of PB-CIRP-102.

FreeRead
PB-CIRP-111
Enterprise IT

Web Shell on Internet-Facing Server

Web shell dropped on an internet-facing server after public-app exploitation — China Chopper, WSO, SharPyShell class. Isolate the host, capture the shell, hunt persistence and credential theft.

FreeRead
PB-CIRP-112
Enterprise IT

C2 Beaconing Detected (Cobalt Strike / Sliver / Generic)

Outbound C2 beacon confirmed. Profile the implant family (Cobalt Strike / Sliver / generic), isolate the host, hunt for peers on the same beacon profile.

FreeRead
PB-CIRP-113
Enterprise IT

LOLBin Abuse on Endpoint (PowerShell / WMIC / Certutil)

Living-off-the-land binary abuse on endpoint — standing-alert response for rundll32 / regsvr32 / mshta / certutil / bitsadmin / wmic / powershell chains. Capture the chain, classify the stage, contain, block fleet-wide.

FreeRead
PB-CIRP-114
Enterprise IT

Credential Dumping (LSASS / SAM / DCSync / NTDS.dit)

Operator response for credential-dumping — LSASS access, SAM/SYSTEM hive copy, NTDS.dit extraction, DCSync from a non-DC, DPAPI / browser secret theft. Pre-encryption credential access is the highest-confidence ransomware precursor; treat every confirmed dump as imminent.

FreeRead
PB-CIRP-115
Enterprise IT

Pass-the-Hash / Pass-the-Ticket Lateral Movement

NTLM hash replay or Kerberos ticket replay across hosts. MDI-driven detection; reconstruct lateral path; contain; rotate KRBTGT twice; validate AD recovery.

FreeRead
PB-CIRP-118
Enterprise IT

Browser Compromise / Session-Token Theft

Infostealer-driven browser compromise — Lumma, Redline or Vidar harvests saved credentials and session cookies; actor replays tokens against SaaS to bypass MFA. Track the host, rotate the credentials, kill the sessions.

FreeRead
PB-CIRP-121
Enterprise IT

Active Directory Enumeration / Attack-Path Discovery

Adversary mapping the directory with BloodHound, SharpHound, PowerView or AdFind. Detect the recon, contain the source host and identity, hunt for what came next.

FreeRead
PB-CIRP-122
Enterprise IT

Email-Delivered Malware (Macro / LNK / ISO / HTML Smuggling)

Email-delivered malware response — the deliverable-variant playbook for macro, OneNote, ISO/IMG, LNK, and HTML-smuggling payloads. Walks the email reconstruction in parallel with endpoint containment.

FreeRead
PB-CIRP-124
Enterprise IT

Web-Application Exploitation (SQLi / SSRF / Deserialisation)

Application-layer compromise — SQLi, SSRF, deserialisation, XXE. Reconstructs the request chain post-WAF-bypass, scopes data impact, contains the host, removes the vulnerable endpoint from the internet.

FreeRead
PB-CIRP-125
Enterprise IT

VPN / Remote-Access Concentrator Compromise (Ivanti / Fortinet / Citrix)

Internet-edge remote-access concentrator compromise — Ivanti Pulse / Connect Secure, Fortinet FortiGate / FortiOS SSL-VPN, Citrix NetScaler / ADC / Gateway. CVE-driven, pre-auth, frequently mass-exploited.

FreeRead
PB-CIRP-201
Cloud & SaaS

AWS Account Compromise

AWS control-plane compromise — IAM key leak, console takeover, federated-role abuse and root-account abuse. Triages, contains and recovers AWS identities, sessions and resources.

FreeRead
PB-CIRP-202
Cloud & SaaS

M365 / Entra ID Compromise

Tenant-wide M365 / Entra ID compromise response — four sub-scenarios spanning Global Admin takeover, mass-mailbox-rule deployment, service-principal credential injection, and conditional-access tampering.

FreeRead
PB-CIRP-203
Cloud & SaaS

OAuth / SaaS Token Abuse

Illicit-consent grants and refresh-token replay across M365, Google Workspace, Slack, GitHub and Atlassian — bounds the OAuth blast radius and revokes the persistence layer.

FreeRead
PB-CIRP-204
Cloud & SaaS

Cloud Storage Data Leak (S3, Azure Blob, GCS)

Object-storage exposure has become an IR — confirmed external access, scrape evidence, or data on the internet. Scope the leak, contain access, assess the privacy-breach footprint, notify.

FreeRead

Showing 24 of 160 matching playbooks. The headline scenarios are free to walk at Community; Pro unlocks the wider catalogue.