High severitySANS PICERL6 steps · 6 phases
SANS Incident Response Process (PICERL)
The canonical 6-phase incident response process from the SANS Incident Handler's Handbook; the foundational framework for all incidents.
Information note
Informational note: The most common mistake in the incident response process is proceeding directly to the cleanup phase before scoping is complete. When the Containment → Eradication → Recovery sequence in the NIST SP 800-61 cycle is violated, the attacker can maintain presence through concealed secondary backdoors. Establish pre-defined decision criteria and exit points for each phase; in particular, do not proceed to the eradication step without documented evidence that the containment phase is complete.
1
Preparation
1 steps- Prepare the IR team, authority, and tools
IR policy, call list, jump-kit, log/EDR/SIEM access, retainer; tabletop exercises.
2
Identification
1 steps- Detect and validate the incident
Alert triage, scoping, IOC collection, incident classification, timeline.
3
Containment
1 steps- Stop the spread (short- and long-term)
Short-term: host isolation / account lockout. Long-term: temporary patches, clean image; acquire forensic copy.
4