Back to Playbooksv1.0.0
Unauthorised Access
Comprehensive incident response playbook for handling unauthorised access and intrusion incidents across the enterprise. Covers detection of suspicious authentication events, analysis of compromised accounts and lateral movement, containment through account lockout and network segmentation, credential resets, perimeter hardening, and post-incident lessons learned based on the NIST Computer Security Incident Handling Guide (SP 800-61).
This playbook follows the NIST Incident Response Framework with 7 phases and 14 total steps.
Response Phases
Click a phase to view its steps, or click a step to view its flowchart