When PowerShell usage is detected in conjunction with a download cradle and external network connection correlation, C2 beacon suspicion, or a lateral movement chain — evidence collection in the correct order and controlled isolation take priority over speed.
Response Playbooks
Incident response flows — step by step, aligned with NIST SP 800-61 and SANS PICERL phases. Structured, technique-driven guides from preparation to recovery.
25 playbooks
Active Directory compromise response: domain admin access, Golden Ticket, DCSync, DC takeover. Systematic recovery to prevent attacker re-entry.