PHISHING Β· RANSOMWARE Β· ACCOUNT ABUSE

Incident Response Playbooks

Actionable response phases for phishing, ransomware, and credential stuffing, from containment through recovery and lessons learned.

A playbook should help responders make the next safe decision under pressure. Keep it short, evidence-led, and tied to named owners.

PHASE 01

Phishing response

Confirm the message, recipients, links, attachments, and any credential use or mailbox-rule changes.

  • Quarantine the message and block confirmed indicators.
  • Reset or revoke sessions for affected accounts.
  • Preserve headers and timeline evidence before cleanup.

PHASE 02

Ransomware response

Contain affected hosts without destroying volatile evidence. Confirm encryption scope, identity activity, backup integrity, and lateral movement.

  • Isolate hosts and disable compromised accounts.
  • Preserve logs, memory evidence, and ransom artifacts.
  • Validate clean backups before restoring.

PHASE 03

Credential stuffing response

Separate normal failed logins from distributed automation, then scope successful logins and affected accounts.

  • Apply targeted rate limits and challenge controls.
  • Invalidate exposed sessions and notify affected users.
  • Review password reset, MFA, and login telemetry.

Frequently asked questions

Should containment wait for perfect attribution?

No. Contain confirmed harmful activity first while preserving enough evidence for investigation.