Incident Response
High scrutiny and high blast radius; proof and governance matter.
This interactive experience is the shipped product itself — the same application code customers run in production, mounted read-only in your browser over a real sample journey. Not a video, not a mockup: because the demo and the product are one codebase, it can never drift from the real thing.
Inside this journey
-
Emergency Intake
Quick qualification to confirm whether an active incident exists, identify decision-makers, and prioritize response urgency.
Intake Questions
Incident Status & Urgency
- Do you have an active incident right now?
- Briefly describe the single most urgent symptom or impact we should know about (one or two sentences)
Authority & Approval
- Who currently holds decision authority to approve an external incident response engagement?
- Is there authorization already in place for an external response team to access systems (retainer, signed PO, verbal OK)?
Technical Scope & Sensitive Data
- Which of these system types are involved or showing suspicious activity?
- Does the incident involve regulated or highly sensitive data we should prioritize (select all that apply)?
Engagement Readiness & Timing
- Is this a retainer customer or an emergency one-off engagement?
- How quickly do you need an incident response team to be engaged?
-
Incident Triage & Discovery
Rapidly map impact, affected systems, data exposure, attacker persistence, and key stakeholders so the seller can recommend immediate actions.
Discovery Questions
Quick Grounding: The Incident Snapshot
- Tell me briefly how this incident first came to your attention.
- In the last 24 hours, what observable symptoms have you seen on affected systems?
- When did you first notice suspicious activity, provide date and approximate time.
- Who is the single person currently coordinating the response on your side?
- Estimate how many endpoints, servers, and cloud instances you believe are affected.
Where the Attacker Actually Lives
- What single persistence mechanism or foothold do you suspect the attacker maintains today?
- Describe any command-and-control indicators you've captured, such as external IPs, domains, or unusual outbound connections.
- Have you observed lateral movement indicators, for example unexpected remote desktop sessions, new admin accounts, or unusual SMB or RPC activity?
- List the security controls or sensors currently collecting telemetry in the affected environment.
- If an active persistence is confirmed, what is the maximum time window you have to contain before business impact becomes irreversible?
What Your Data and Systems Really Mean to the Business
- How would you rank the business criticality of the systems you believe are affected, from mission-critical to low-impact?
- Which categories of sensitive data may be involved, select all that apply.
- Approximately how many unique user records or files do you estimate could be impacted?
- What percentage of your customer-facing traffic runs through the potentially affected systems?
- Why would disclosure or compromise of the identified data categories trigger regulatory or contractual notifications for your organization?
Who Must Be at the Table Right Now
- Name the three roles inside your organization who must approve containment actions immediately.
- Confirm whether legal counsel or insurer approval is required before making configuration changes or taking systems offline.
- Which communication channels does your executive team expect to be used for incident updates?
- Walk me through your escalation path for C-suite notification, including thresholds or impact levels that trigger it.
- If a forensic hold is needed, who has the legal authority to issue it and how quickly can it be enacted?
Hidden Barriers That Slow an Emergency Response
- Where does your current approval or procurement process cause the most delay in enacting emergency containment?
- Have you experienced a recent incident where access or credentials were not handed over in time, and what happened as a result?
- Identify the third-party vendors or managed service providers who must be contacted during a response.
- How resilient are your off-site backups, and have you tested recovery from them within the last 6 months?
- Describe any contractual clauses with vendors that could prevent immediate forensic access or data transfer.
Who Else Could You Call or Keep Doing This Yourself?
- List the external response options you are evaluating or have used in the past 24 months.
- For each option you listed, what would have to go right for you to stick with it instead of changing vendors?
- Has anyone on your executive team formally proposed handling this incident entirely in-house?
- Name one capability the incumbent or your internal team would need to demonstrate to keep your business from engaging an outside firm.
- Approximately how long are you willing to wait for a first remote or on-site engagement from an external responder before considering internal containment only?
Operational Readiness and Practical Gates
- Confirm whether your team can provide administrator-level access to affected endpoints and cloud control planes within 4 hours.
- Identify the network segments, cloud accounts, or VPCs we must prioritize for sensor deployment.
- Do you have legal holds, preservation notices, or regulatory gates that would limit forensic collection or cross-border data transfer?
- Estimate the size of logs and telemetry we can retrieve for initial triage, in gigabytes per day.
- Are there contractual or regulatory notification timelines that will constrain our investigation steps?
If We Took This On, Here's What We Would Need Today
- Tell us the single most important artifact we must collect first to validate attacker activity and why.
- Provide a prioritized list of up to 10 fully qualified hostnames, IPs, or cloud instance IDs for immediate sensor targeting.
- Do you have pre-provisioned credentials, a jump-box, or emergency access method we can use to begin remote collection, and how are they delivered?
- Specify any data retention or export restrictions that will affect how we store collected packet captures, disk images, or memory snapshots.
- Within what timeframe can your identity provider or authentication team revoke or rotate compromised credentials if we recommend it?
Closing the Gap: Immediate Next Steps That Move the Clock
- Assuming initial triage shows active exfiltration, what is the single authorization we would need to proceed to containment within your organization?
- On a scale of 1 to 5, how comfortable is your board or executive leadership with a temporary outage of customer-facing services to stop data loss?
- Summarize the minimum timeline you need from engagement acceptance to active containment, in hours.
- Select the outcomes that would make you sign an emergency engagement immediately.
- Finally, who should receive the initial statement of work and emergency authorization so we can meet your preferred SLA?
-
Response Overview & Capabilities
Walk through how the seller will investigate, contain, and recover in the buyer's environment, including expected timelines and coordination points.
Solution Experience
- Response Overview & Capabilities
- Confirm the current state and its cost to your team
- You confirm the investigation scope and evidence types fully cover the systems and data you are most concerned about.
- Deliver a tailored investigation and containment plan with named owners and timelines within 24 hours of this session.
- You confirm the containment approach and its expected impact on availability are acceptable for your business priorities.
- Prove the investigation approach and timelines
- Provide a prioritized list of critical systems, system owners, and admin contacts, plus any known logging endpoints and recent back-ups.
- Prove the containment and eradication play and expected impact
- Provide primary legal and insurer contact details and any contractual notification timelines that must be met.
- You confirm the recovery timeline and the named coordination points for legal and insurer notifications meet regulatory and contractual windows.
- Prove the recovery and business continuity timeline
- You agree on immediate authorizations and the seller deliverable that will be provided after this session.
- Provide written authorization to proceed with emergency triage and sensor deployment when the engagement terms are agreed.
- Confirm coordination points with legal, insurers, and authorities
- Validate the proposed approach
- Agree immediate next steps and authorizations
- Response Overview & Capabilities, Solution Experience
- Response Overview Deck
- Response Overview Brief
- meeting
- slides
- document
-
Engagement Scope
Define services (triage, forensic collection, containment, eradication, recovery), deliverables, responsibilities, and reporting expectations.
Scope Configuration
- Deploy forensic sensor network
- Capture memory and volatile data
- Collect full packet capture and preserve evidence
- Acquire endpoint telemetry and disk images
- Rapid incident triage and scope determination
- Threat intelligence correlation and IOC hunting
- Attack infrastructure mapping and disruption
- Contain and isolate compromised systems
- Malware reverse engineering and IOC generation
- Malware removal and host reimaging
- Credential revocation and privilege remediation
- Data exfiltration analysis and file reconstruction
- Restore systems and validate business processes
- Deliver post-incident forensic report and evidence package
- Coordinate law enforcement and outside counsel engagement
Scope Questions
Deploy forensic sensor network
- Specify the network segments and cloud regions where you need forensic sensors deployed (for example: corporate VLANs, DMZ, AWS us-east-1).
- Provide an estimate of endpoints by type to cover with sensors (Windows servers, Linux hosts, network appliances, OT devices).
- Identify your current Endpoint Detection and Response (EDR) and Security Information and Event Management (SIEM) coverage and the integration endpoints we can use.
- List any network access constraints or approved change windows that would affect sensor installation (maintenance windows, change freeze dates).
- Indicate required sensor telemetry retention and access controls for captured data (retention days, access roles, encryption at rest).
Capture memory and volatile data
- Identify high-priority hosts for live memory capture (domain controllers, mail servers, privileged admin workstations).
- Provide preferred time windows or blackout periods when live acquisition is permitted.
- State any legal hold or preservation orders that affect volatile data handling and chain-of-custody.
- Detail available remote access methods for acquisition (management agent, console access, out-of-band KVM).
- Estimate the number of concurrent memory captures you require and the maximum acceptable duration per capture.
Collect full packet capture and preserve evidence
- Specify the network taps, SPAN ports, or cloud packet-collection endpoints you can provide for full packet capture; include device names or tags where possible.
- Indicate the target retention period and permitted storage locations for packet captures to satisfy evidence preservation.
- Confirm the acceptance criteria for the packet capture evidence package, including chain-of-custody documentation and checksum method (for example SHA256).
- List bandwidth or storage constraints on mirror ports that could limit sustained packet collection (for example: 1 Gbps mirror, 10 Gbps mirror).
- Decide if selective capture filters are required by subnet, IP range, or application protocol to limit scope.
Acquire endpoint telemetry and disk images
- Name the priority hosts for full disk imaging (for example: database servers, mail servers, key executive workstations).
- Describe available imaging methods and credentials we can use (physical access, management console, agent-based image).
- Confirm acceptable image formats and verification methods for forensic use (for example: forensic image with SHA256, E01, raw/dd).
- State required forensic mounting or preservation restrictions for imaged disks (read-only, air-gapped storage, encrypted archive).
- Estimate total disk capacity to be imaged and note any encrypted volumes that will require keys.
Rapid incident triage and scope determination
- Share the initial indicators of compromise you have observed (suspicious IP addresses, file names, ransom notes, unusual processes).
- Supply the time window for triage (from detection timestamp to now) in ISO date-time or relative hours.
- Name the business systems you want prioritized for scope (customer-facing services, billing systems, Active Directory).
- Select your acceptable triage service-level objective for initial impact assessment.
- Clarify whether encrypted or backup systems should be excluded from immediate containment pending legal guidance.
Threat intelligence correlation and IOC hunting
- Share any existing indicators of compromise (IOCs) you can provide now (file hashes, domains, IPs, YARA rules).
- Select the internal telemetry sources we should query for IOC hunting (EDR, SIEM, firewall logs, cloud audit logs).
- Choose enrichment requirements for threat intelligence correlation (for example passive DNS, whois, sandbox results).
- Define the lookback window for IOC hunting across logs and telemetry (hours, days, weeks).
- Choose whether automated blocking of matched IOCs at network or endpoint controls is permitted during hunting.
Attack infrastructure mapping and disruption
- Enumerate public-facing assets and domains to include in infrastructure mapping (websites, mail exchange records, VPN endpoints).
- Disclose any known attacker infrastructure indicators you already have (command and control domains, hosting providers, IP lists).
- Describe legal or policy constraints for disruption activities that could affect third-party infrastructure.
- Supply preferred coordination points for takedown or blocking actions (ISP contacts, registrar contacts, national computer security incident response team).
- Clarify whether you require notification templates or an approval workflow before we contact hosts or registrars.
Contain and isolate compromised systems
- Outline the isolation methods permitted for containment (network ACLs, host quarantine via EDR, switch port isolation).
- Declare systems that must remain online for business continuity and cannot be isolated (for example billing servers, telephony systems).
- Define acceptable timing for containment actions relative to executive or counsel approval.
- Describe required rollback procedures in case containment causes a service outage.
- Detail monitoring checks we should run to verify isolation effectiveness (for example: no outbound C2, no SMB to unknown hosts).
Malware reverse engineering and IOC generation
- Upload status of suspected malware samples for analysis (available now, available on collection, none available).
- Which level of analysis is required: static analysis, dynamic sandboxing, or full reverse engineering?
- Which IOC formats and delivery mechanisms do you require for signature deployment (for example YARA, Snort rule, Sigma, STIX)?
- Declare whether you need obfuscated IOC variants, raw indicators, or both for deployment in your controls.
- Flag any restricted environments where malware analysis must not send telemetry (for example: air-gapped labs, regulated data environments).
Malware removal and host reimaging
- Outline the criteria you require before a host is considered cleaned and eligible for reimaging (for example: no persistence, clean checksums, current patches).
- Recommend your preferred reimaging method for infected hosts (golden-image deployment, rebuild from scratch, restore from backup).
- Report the owner of recovery images and whether update permission can be granted to update golden images when remediations are applied.
- Document required malware-free validation checks post-reimaging (for example: EDR scan results, offline hash compare, SIEM reconciliation).
- Are rollback plans required if reimaging affects business workflows?
Credential revocation and privilege remediation
- Enumerate credential stores and identity providers in scope (for example Active Directory, cloud identity provider, single sign-on provider).
- Report privileged accounts and service accounts that require credential rotation, including any emergency elevation accounts.
- Define required password rotation policies and multi-factor authentication resets (for example force reset, rotation within 24 hours).
- Are temporary disabling of accounts permitted as part of remediation?
- Verify whether service account credentials are stored in a secrets manager and whether access will be provided for remediation.
Data exfiltration analysis and file reconstruction
- Collect the list of data sources we should use for exfiltration analysis (for example proxy logs, data loss prevention logs, cloud object storage access logs).
- Prioritize sensitive data repositories to focus on for reconstruction (for example customer databases, financial ledgers, email archives).
- Recommend the acceptable reconstruction fidelity threshold (complete file recovery, partial metadata, SHA256 match).
- Document required notification thresholds if confirmed exfiltration of regulated data occurs (for example personally identifiable information, protected health information).
- Do you require proof-of-possession artifacts for regulator or insurer reporting (for example hash lists, sample files) and at what level of sampling?
-
Mutual Commit
Confirm engagement type (retainer or emergency), commercial terms, response SLAs, authorization to proceed, and coordination with counsel and law enforcement.
Agreement Modules
- Master Services Agreement (MSA)
- Statement of Work (SOW)
- Engagement Order Form
- Service Level Agreement (SLA)
- Emergency Authorization to Proceed
- Fee Schedule & Payment Terms
- Law Enforcement & Counsel Coordination Authorization
- Data Processing Addendum (DPA) — conditional
-
Response Execution
Lock access, schedules, and technical parameters, then run the response plan with clear owners and escalation paths.
-
Operational Readiness
Lock concrete readiness facts the seller needs before active work — system owners, admin access, logging endpoints, legal holds, and insurer or counsel contacts.
Pre-Deployment Questions
Environment and access
- Which environment categories will the seller need access to for active response? (select all that apply)
- Are named system owners and on-shift technical contacts identified for each environment above? (so we can request access and approvals immediately)
- If any owners/contacts are missing or partial, list the environment name and the designated technical owner's name, title, and daytime contact (one line per environment)
Access and administrative readiness
- Is privileged administrative access available to the seller, or will the seller require temporary break‑glass/vendor accounts? (this determines our initial deployment method)
- If admin access requires approval, provide the approver's name, role, and expected approval turnaround (business hours) so we can schedule first actions.
Logging, telemetry, and collection endpoints
- Are centralized logging and telemetry endpoints reachable and authorized for seller ingestion (SIEM/cloud logs/packet capture/EDR telemetry)? (this tells us whether we should ingest existing feeds or deploy sensors)
- For any 'Partial' or 'No' responses above, indicate which categories need completion (select all that apply)
Legal, insurance, and coordination constraints
- Has legal issued a preservation order or legal hold covering systems/data relevant to this incident? (we need to know before collecting evidence)
- Provide the primary legal contact and the primary insurer or retainer contact (name, role, and best daytime contact). Also call out any immediate regulatory notification deadlines or law‑enforcement involvement we must honor before taking evidence.
- Are there blackout windows, maintenance windows, or business constraints (by site or region) that would prevent sensor deployment or containment actions during the next 72 hours? If yes, list the window(s) and the responsible approver.
- If you indicated blackout/maintenance windows above, list each site/region, the blackout window (local time), and the approver we must coordinate with.
Final go/no-go readiness checks
- Overall, is the buyer authorizing the seller to proceed with active sensor deployment and forensic collection once initial access approvals are confirmed?
- If authorization is deferred or limited, name the decision owner(s) and the expected date/time they will provide formal authorization.
-
Response Configuration
Provide exact technical access and collection parameters — endpoint lists, sensor targets, credentials, packet-capture scope, and retention requirements the seller will use.
Configuration Details
Response Configuration — Technical access & collection parameters
- Which deployment environment does this configuration apply to? (Default: Production)
- Provide the canonical endpoint target list file URL or storage path the seller will ingest for deployment and collection (enter a single HTTPS or S3-style URL; format: https://... or s3://...; enter 'none' if no preexisting list)
- Select the category of system that is the authoritative source for the endpoint list you provided (choose one)
- Provide the identifier/name of the account or service that owns the deployment credential (credential identifier only — DO NOT paste secrets). Example: 'ir-deploy-service-account'
- Confirm the secure channel to be used to exchange credentials and secrets at kickoff (Default: your secrets manager)
- Select the primary authentication method the seller will use to access endpoints (choose one). Default: SSH key-based for Linux / WinRM for Windows
- Provide the single jumpbox / bastion host hostname or IP the seller will use if remote access requires a jumpbox (enter 'none' if not used)
- Primary network capture target — enter a single CIDR block or VLAN identifier the seller should prioritize for packet capture (enter 'all' to capture all internal ranges)
- Packet-capture duration per interface in minutes (numeric). Default is 60 — enter an integer number of minutes the seller should capture per session
- Packet-capture retention in days for full PCAPs stored in the seller's collection store (numeric). Default is 7 days — enter an integer number of days
- Endpoint telemetry / EDR artifact retention in days the seller should maintain collected telemetry for investigation (numeric). Default is 90 days — enter an integer number of days
- Provide any packet-capture filter expression or the single URL to a filter file the seller should apply (enter a BPF-style expression, a single file URL, or 'none' to use full-capture)
-
Active Response & Containment
Execute sensor deployment, forensic collection, containment, eradication, and recovery with named owners, timelines, and escalation rules.
-
-
Incident Closure & After-Action
Review findings, confirm attacker removal and data impact, deliver final forensic and disclosure reports, and track remediation actions and enhancement requests.
Success Reviews
- Closure Readout and Verification
- First Measurement, Outcomes and Gaps
- Acceptance Gate, Final Forensic Report and Closure Decision
- Quarterly Remediation Progress and Lessons Review
Issues & Enhancements
- Prepare a regulatory status brief for distribution to legal and insurer contacts if any open reporting items remain.
- Restate acceptance criteria and numeric targets
- Produce a documented acceptance decision for the final forensic and disclosure reports against the criteria recorded in Mutual Commit and Engagement Scope.
- Confirm that attacker removal verification is complete or document any conditional verification steps with deadlines.
- Establish the final remediation closure schedule and the evidence handoff plan for legal and regulatory teams.
- Publish the signed acceptance decision and archive the final forensic evidence package to the agreed retention location.
- Capture and circulate the final remediation schedule with dates for each remaining item and acceptance criteria for closure.
- Deliver the disclosure-ready summary and evidence bundle to counsel and insurer as agreed.
- If conditional acceptance, enumerate the conditional items and set verification dates for re-evaluation.
- Remediation progress dashboard
- Confirm remediation percent complete meets the target recorded in Mutual Commit or document the remediation runway to meet it.
- Identify and schedule remediation of any remaining high-risk residues and confirm projected close dates.
- Agree specific playbook updates and a date for the next tabletop exercise to validate improvements.
- Update the remediation tracker with the current percent complete and revised close dates for outstanding items.
- Create a prioritized list of playbook and tooling enhancements and assign implementation windows for the next quarter.
- Schedule a tabletop exercise to validate the updated playbook and monitoring configurations.
- Reconfirm scope, SLAs, and evidence retention requirements
- Confirm technical evidence supports attacker removal and list any outstanding verification work.
- Deliver a prioritized remediation action list and agree owners and target dates for immediate items.
- Confirm final forensic report delivery date and required artifacts for legal and insurer review.
- Produce and circulate the interim forensic evidence package and verification checklist.
- Schedule and perform any outstanding verification scans or telemetry correlation tasks.
- Publish the prioritized remediation action list into the shared tracker with target completion dates.
- Assemble materials required by counsel and insurer and confirm delivery method and timing.
- Present measured outcome metrics
- Determine whether mean time to attacker removal and confirmed compromised asset counts meet targets recorded in Mutual Commit, or document specific corrective actions if not.
- Ensure all high-risk remediation items have owners and closure dates that align to the acceptance gate timeline.
- Confirm regulatory disclosure readiness and identify any missing evidence needed for filings.
- Update the remediation tracker with owners, priority, and firm completion dates for all high-risk items.
- Perform targeted verification scans to close outstanding compromised-asset confirmations.
- Produce a gaps-and-mitigation brief tying each missed metric to a corrective action and timeline.
- Confirm acceptance gate meeting date and circulate the required deliverables checklist for that meeting.
- Validate attacker removal and containment evidence
- Present final forensic findings and evidence package
- Risk residue and residual exposure review
- Root-cause review for any metric shortfalls
- Demonstrate verification of attacker removal
- Regulatory, insurer, and stakeholder status update
- Remediation progress and blockers
- Review interim forensic findings and delivered artifacts
- Lessons learned and playbook updates
- Document pass/fail per acceptance criterion and capture the acceptance decision
- Disclosure and regulatory readiness check
- Present remediation action list and initial prioritization
- Agree corrective action plan and timeline to acceptance gate
- Finalize outstanding remediation schedule and disclosure handoff
- Legal, disclosure, and insurer coordination checklist
- Enhancement requests and next-quarter priorities