Knowledge / IR detection

IR playbook

A written path for a class of incident. Roles, decisions, and evidence. Not a novel, and not a blank page at 2 a.m.

An incident response playbook is the procedure for a type of event: ransomware, business email compromise, lost laptop, stolen token. Who is called, what is preserved, what may be contained, who talks outside. Incident response is the discipline; this is the artefact you actually run.

Keep it short enough to use. Exercise it. A playbook that still names someone who left is a liability. Pair it with logging you already have, or the steps are fiction.

See also: Incident response, Logging, Security operations centre, Threat hunting.