Security
Security
41 skills in Security.
41 skills in this category.
Account Takeover Runbook
An account is confirmed or strongly suspected compromised — run the full response: disable sign-in, revoke sessions, reset MFA, sweep inbox rules and consents, assess blast radius, and notify.
Breached Credential Response
A user's credential is confirmed exposed and likely current — notify the user, drive rotation everywhere the password was reused, and verify MFA before standing down.
Business Email Compromise Recovery
A BEC is confirmed (not just suspected) — a client mailbox was taken over and used for fraud — run the full recovery: kill sessions and tokens, sweep rules and forwarding, assess and notify downstream victims, and follow the money.
Compromised Account Containment
An account needs containing NOW — run the rapid checklist (block sign-in, revoke sessions, reset password, sweep MFA and rules) and timestamp every step in the ticket note.
Credential Stuffing Response
A pattern of failed/anomalous logins across many accounts points to password spraying or credential stuffing — scope the attack, lock down, and rotate the accounts that actually fell.
Cyber Risk Posture Review
A client's security posture needs reviewing — combine the cyber risk dashboard, identity data, open detections, and incident history into a posture summary with the top ranked risks.
Dark Web Alert Lifecycle
A dark-web or credential-exposure monitoring alert arrived — age it, close stale exposures with a documented note, and notify affected users with rotation guidance on fresh ones.
Defensive Writing Standard
Base language standard for anything security-related a client might read — load it whenever drafting security notifications, incident updates, postmortems, or alert closures so the wording never overstates what is confirmed.
DLP Alert Triage
A data-loss-prevention alert fired — someone emailed, uploaded, or copied something the policy watches — separate business-process false positives from real exfiltration signals, investigating with respect for employee privacy.
DMARC SPF Failure Triage
A ticket involves email authentication failures (SPF, DKIM, DMARC) — determine whether it's a real spoofing attempt or a sender misconfiguration, and explain it to the client safely.
Domain Expiry Alert Lifecycle
A registrar expiry, renewal, or "your domain is about to lapse" notice arrived as a ticket — verify the sender is the real registrar FIRST (renewal-invoice scams are a classic BEC lure), confirm the actual expiry date independently, identify who owns the renewal, and route with a timeline.
EDR Detection Runbook
An EDR suspicious-process or malware detection alert landed — pull device context from the RMM, check what the EDR already contained, confirm with the device user, and escalate or close with evidence.
Email Header Analysis
Someone pasted raw email headers and wants a verdict — parse authentication results, the received path, and spoof indicators, and return a verdict with explicit confidence.
Global Admin Audit
Audit a client's global/company administrator accounts and recent admin-role changes — flag unexpected admins, missing MFA, and grants with no authorizing ticket.
Identity MFA Health Check
Review a client's identity hygiene — MFA coverage, privileged accounts, and stale accounts — and return ranked findings with remediation recommendations.
Impossible Travel Runbook
An impossible-travel or atypical-location sign-in alert fired for a user — check VPN and travel explanations, verify with the user via a number on file, and contain on confirmed account takeover.
Inbox Rule Alert Runbook
An alert fired for a suspicious inbox rule created on a user's mailbox — judge legitimacy, inventory all rules, and remove plus rotate if malicious.
Insider Risk Basics
A ticket smells like insider risk — data staging by a departing employee, sabotage signs, access abuse — the rule is DO NOT investigate solo: preserve evidence quietly, escalate to client leadership/HR per policy, and keep it confidential.
Lost or Stolen Device Response
A user reports a lost or stolen laptop or phone — work the lock/wipe decision, assess what data and access were on it, and drive the carrier/police steps, with the destructive actions gated on explicit approval.
MDR Client Onboarding
A client is being onboarded to a new MDR/SOC service — scope the assets, wire alert routing into the desk, record escalation contacts and authority, and set baseline-noise expectations for the first weeks.
MFA Fatigue Attack Response
A user is getting a flood of MFA push prompts they didn't start (push bombing / MFA fatigue) — treat the password as already known, contain the account, and drive the tenant toward number-matching so approval spam stops working.
Monthly Security Report
Produce a client's monthly security digest — incident and alert counts by type, notable events, posture trend, and recommendations — ready for the client edition or the internal review.
New User Created Alert
An alert fired for an unexpected user or admin account creation in a client tenant — cross-check for an authorizing ticket before raising alarm, and contain if no one can claim it.
OAuth Consent Grant Abuse
A malicious or over-privileged third-party app has an OAuth grant into a client's tenant (illicit consent / consent phishing) — identify the grant, revoke it, and tighten tenant consent policy so it can't recur.
Phishing Simulation Program
Plan or coordinate a phishing-awareness simulation campaign for a client — scope, cadence, lure difficulty, a no-shame reporting culture, and keeping the desk's triage from colliding with the simulation.
Phishing Triage
A user reported a suspicious email or a phishing-report ticket landed on the security board — assess it without touching the payload, check blast radius, contain if malicious, and reply to the reporter with a verdict.
Quarantine Release Request
Someone asked to release a quarantined email — verify the requester, assess why the filter caught it, and recommend release or refusal with the reasoning documented.
Ransomware Response
Ransomware is suspected or confirmed at a client — encrypted files, ransom notes, mass file renames, or an EDR ransomware verdict. Run the defensive IR sequence: isolate, verify backups BEFORE touching them, engage IR/insurance per policy, and sequence recovery.
Security Alert Response
A security alert ticket arrived (SOC detection, sign-in anomaly, breached credential, dark web, user-created alert) — extract the facts, route it to the right client, tier the severity, and contain or close with documented reasoning.
Security Incident Postmortem
A security incident is resolved and needs a postmortem — build the executive summary, timeline, impact, root cause, and action items from ticket evidence, in defensible language.
Security Noise Tuning
The same benign security alert keeps firing — quantify the false-positive rate, build an evidence pack, and recommend a retune at the source tool instead of ignoring it in the queue.
Security Onboarding New Client
A new client is being onboarded and their security baseline is unknown — run the intake: MFA coverage, admin inventory, backup posture, EDR presence — and produce the day-one risk list before the first incident finds the gaps for you.
Session Token Theft Response
An account shows malicious activity even though MFA passed and the password looks fine — a stolen session cookie or token is in play, so revoke sessions and tokens, not just the password.
SOC Classification Tree
Classify a security-board ticket down the Incident/Request/Problem tree and set type, subtype, and item consistently — use whenever a security ticket needs classification or a tech asks how to categorize an alert.
SOC Client Email Pack
A security event needs its first client outreach — pick the per-threat-type template (leaked credentials, vendor fraud/BEC, inbox rule, lookalike domain), fill it with verified facts only, and present a draft.
SOC Shift Handoff
Security-desk shift change with investigations in flight — hand off open security work with evidence state, containment-in-progress status, and watch items, so the incoming shift can act in minute one without re-deriving anyone's reasoning.
Typosquat Domain Alert
A lookalike or typosquatted domain impersonating a client was reported or detected — gather registrar and DNS facts without visiting it, gauge attack capability, and draft the client warning.
Vendor Fraud BEC Alert
A business-email-compromise or payment-fraud attempt was reported (fake invoice, banking-change request, executive impersonation) — freeze pending payments, run the callback verification ladder, and investigate the message.
Vulnerability Report Triage
A vulnerability report arrived — a CVE from a scanner, a vendor advisory, or an external researcher's disclosure — and needs an honest severity-vs-exploitability read, an affected-asset check, and a patch-or-mitigate plan.
Wire Fraud Verification Protocol
The callback-verification standard for ANY request to change or add payment details — banking changes, new wire instructions, payroll redirects — verify out-of-band to a number on file before anything moves, no exceptions.
Zero-Day Emergency Response
A vendor 0-day dropped — actively exploited, no patch or an emergency patch just released — and every client's exposure must be counted, mitigated, and communicated tonight, not next patch cycle.
Was this page helpful?
⌘I