On template/CA change, canary alert, or discovery tool detection with no evidence of active exploitation, close the vulnerability, identify the source, and apply permanent hardening.
Response Playbooks
Incident response flows — step by step, aligned with NIST SP 800-61 and SANS PICERL phases. Structured, technique-driven guides from preparation to recovery.
50 playbooks
Steps to collect evidence, remove the ACE, and close the attack path when an unauthorized ACE modification is detected on an unprotected individual AD object.