Generic incident response playbook template following NIST SP 800-61 and PICERL frameworks.
25/04/2026
#playbook
#incident-response
#soc
#nist
#picerl
SOC Playbook Template — Generic Incident Response
This template follows the NIST SP 800-61 and PICERL frameworks.
Duplicate and fill in for each new scenario (RDP Brute Force, Phishing, Malware, etc.)
Reference Frameworks
NIST SP 800-61 — 4 phases
Phase
Name
Description
1
Preparation
Policies, tools, and playbooks in place before any incident
2
Detection & Analysis
Triage, qualification, and scoping of the incident
3
Containment, Eradication & Recovery
Isolate, clean up, restore to normal operations
4
Post-Incident Activity
Debrief, lessons learned, continuous improvement
PICERL — 6 phases
Letter
Phase
Description
P
Preparation
Same as NIST — tools, procedures, team readiness
I
Identification
Detect and confirm the incident (triage)
C
Containment
Short-term (isolate) then long-term (patch, harden)
E
Eradication
Remove the root cause (malware, account, vulnerability)
R
Recovery
Restore and validate return to normal operations
L
Lessons Learned
Post-mortem, playbook update, process improvement
Section 1 — Metadata
Field
Value
Playbook ID
PB-XXX-000
Scenario
e.g. RDP Brute Force
Default severity
Low / Medium / High / Critical
MITRE ATT&CK
e.g. T1110.001, T1021.001
Applies to
e.g. Windows Server, endpoints
Detection source
e.g. SIEM, EDR, IDS
Author
Last updated
Section 2 — Threat Description
Describe the attack: mechanism, common tools (Hydra, Medusa, etc.), attacker objective, and enabling conditions (no NLA, no lockout policy, exposed port, etc.)
Section 3 — Detection Signals
Abnormal volume of failed authentication events (above defined threshold)
Same source IP, same targeted account
Regular interval between attempts (automated pattern)
Successful logon event in the same time window → immediate escalation