Showing 12 of 12 playbooks
Comprehensive response to malware incidents including containment, eradication, and recovery
Handle credential harvesting and email-based attacks
Respond to unauthorized access or exfiltration of sensitive data
Respond to distributed denial of service attacks
Investigate suspicious activity by internal users
Comprehensive response to ransomware encryption attacks
Respond to prompt injection, model/data poisoning, and sensitive-data leakage in AI and LLM systems
Respond to operational technology and SCADA incidents while preserving safety and process integrity
Respond to web exploitation such as SQL injection, XSS, authentication bypass, and web shells
Respond to post-compromise network intrusions involving credential abuse and lateral movement
Respond to cloud account and workload compromise including IAM abuse, exposed storage, and cryptomining
Respond to third-party, dependency, or software supply-chain compromises affecting the build and delivery pipeline
Critical
High Priority
Total Playbooks
Categories