SOC Playbook Template — Generic Incident Response

Generic incident response playbook template following NIST SP 800-61 and PICERL frameworks.

25/04/2026

#playbook #incident-response #soc #nist #picerl

SOC Playbook Template — Generic Incident Response

This template follows the NIST SP 800-61 and PICERL frameworks.
Duplicate and fill in for each new scenario (RDP Brute Force, Phishing, Malware, etc.)


Reference Frameworks

NIST SP 800-61 — 4 phases

PhaseNameDescription
1PreparationPolicies, tools, and playbooks in place before any incident
2Detection & AnalysisTriage, qualification, and scoping of the incident
3Containment, Eradication & RecoveryIsolate, clean up, restore to normal operations
4Post-Incident ActivityDebrief, lessons learned, continuous improvement

PICERL — 6 phases

LetterPhaseDescription
PPreparationSame as NIST — tools, procedures, team readiness
IIdentificationDetect and confirm the incident (triage)
CContainmentShort-term (isolate) then long-term (patch, harden)
EEradicationRemove the root cause (malware, account, vulnerability)
RRecoveryRestore and validate return to normal operations
LLessons LearnedPost-mortem, playbook update, process improvement

Section 1 — Metadata

FieldValue
Playbook IDPB-XXX-000
Scenarioe.g. RDP Brute Force
Default severityLow / Medium / High / Critical
MITRE ATT&CKe.g. T1110.001, T1021.001
Applies toe.g. Windows Server, endpoints
Detection sourcee.g. SIEM, EDR, IDS
Author
Last updated

Section 2 — Threat Description

Describe the attack: mechanism, common tools (Hydra, Medusa, etc.), attacker objective, and enabling conditions (no NLA, no lockout policy, exposed port, etc.)

Section 3 — Detection Signals

Section 4 — Triage & Qualification (Identification)

Section 5 — Containment

Section 6 — Eradication

Section 7 — Recovery

Section 8 — Lessons Learned & Improvement

Section 9 — Escalation Criteria (L1 → L2)

FieldValue
Escalate ifSuccessful logon detected / internal machine compromised / admin access confirmed
Escalate toL2 Analyst / IR Team / CISO
Max delay before escalatione.g. 30 min after detection

IOCs Template

TypeValueNotes
Source IPAttacking machine
Target IPTargeted machine
PortTargeted service
AccountTargeted account
Event IDRelevant Windows/Linux event
ToolAttack tool if identified

MITRE ATT&CK Mapping

TacticTechniqueID

Timeline

TimeEvent

Verdict & Outcome

Verdict: True Positive / False Positive / Benign
Severity justification:
Escalated to:

Remediation status

ActionStatus
done / monitoring / pending
done / monitoring / pending

References: NIST SP 800-61 Rev. 2 · PICERL (SANS Institute) · MITRE ATT&CK