Skip to content

Find a playbook

Map alert titles to playbook files. Multiple alerts can share the same playbook. The agent reads this index first to find the right playbook for the current investigation.

  1. Match the alert title (from xdr incidents show <id> --expand alerts) against the Alert title column.
  2. If a match is found, read the linked playbook file before continuing the investigation.
  3. If no match is found, fall back to the general methodology in docs/investigation.md.

Matching is substring / fuzzy — e.g., an alert titled 'Rimecud' malware was prevented matches the Rimecud row.

Alert title (or keyword)PlaybookNotes
Creation of forwarding/redirect ruleemail-forwarding-rule.mdInbox rule forwarding — DLP focus
Creation of email forwarding ruleemail-forwarding-rule.md
Suspicious inbox manipulation ruleemail-forwarding-rule.mdInbox manipulation — deletion/move rules to cover tracks
Suspicious Outlook rulesemail-forwarding-rule.md
Rimecudendpoint-malware-generic.mdUSB-propagating worms (Rimecud, Gamarue, Jenxcus)
Gamarueendpoint-malware-generic.md
Jenxcusendpoint-malware-generic.md
Hamweqendpoint-malware-generic.md
Autorunendpoint-malware-generic.md
Impossible travel activityidentity-impossible-travel.mdIdentity anomaly — sign-in from geographically distant locations
Atypical travelidentity-impossible-travel.md
Mass downloaddlp-data-exfiltration.mdBulk file downloads, external sharing, departing-user data theft
Unusual amount of external file activitydlp-data-exfiltration.md
Data theft by departing usersdlp-data-exfiltration.mdPurview IRM policy
Email messages containing malicious file removed after deliveryemail-malicious-delivery.mdZAP removals and failed removals
Email messages containing malicious URL removed after deliveryemail-malicious-delivery.md
Email messages from a campaign removed after deliveryemail-malicious-delivery.md
Email messages removed after deliveryemail-malicious-delivery.md
Messages containing malicious entity not removed after deliveryemail-malicious-delivery.mdThreat identified but ZAP failed
potentially malicious URL clickemail-malicious-url-click.mdURL clicks, phishing site access, HTML phishing
Device tried to access a phishing siteemail-malicious-url-click.md
HTML attachment phishing attemptemail-malicious-url-click.md
Phishing documentemail-malicious-url-click.md
User accessed a link in an email subsequently quarantined by ZAPemail-malicious-url-click.md
Suspicious email sending patternsemail-suspicious-sending.mdSuspicious outbound email, account used for spam
User restricted from sending emailemail-suspicious-sending.md
Command and Control behaviorendpoint-command-and-control.mdC2 beaconing, suspicious network connections
Connection to a custom network indicatorendpoint-command-and-control.md
Suspicious connection blocked by network protectionendpoint-command-and-control.md
Horizontal port scanendpoint-command-and-control.md
malware was detectedendpoint-malware-generic.mdGeneric AV/EDR detections (no family-specific playbook)
malware was preventedendpoint-malware-generic.md
detected on one endpointendpoint-malware-generic.md
Malware incidentendpoint-malware-generic.md
Malware detectionendpoint-malware-generic.md
Multiple threat familiesendpoint-malware-generic.md
Suspicious files incidentendpoint-malware-generic.md
Unwanted software incidentendpoint-malware-generic.md
Endpoint attack notificationsendpoint-malware-generic.mdDrive-by download, infostealer campaigns
hacktool was detectedendpoint-malware-generic.md
unwanted software was detectedendpoint-malware-generic.md
unwanted software was preventedendpoint-malware-generic.md
behavior was blockedendpoint-malware-generic.mdAMSI/behavioral blocks (ClickFix, PShellCobStager, etc.)
Ransomwareendpoint-ransomware.mdRansomware indicators, CVE exploitation with ransomware
adversary-in-the-middleidentity-aitm-phishing.mdAiTM phishing proxy — session token theft
AiTMidentity-aitm-phishing.md
Anomalous Tokenidentity-anomalous-token.mdToken theft / replay indicators
Potential user account compromiseidentity-anomalous-token.md
Password Sprayidentity-password-spray.mdPassword spray attacks
Activity from a password-spray associated IPidentity-password-spray.md
Activity from a TOR IP addressidentity-risky-sign-in.mdTOR, proxy, unfamiliar properties, malicious IP
Activity from an anonymous proxyidentity-risky-sign-in.md
Anonymous IP addressidentity-risky-sign-in.md
Unfamiliar sign-in propertiesidentity-risky-sign-in.md
Malicious IP addressidentity-risky-sign-in.md
Suspicious impersonated activityidentity-risky-sign-in.md
Suspected brute-force attackmdi-identity-attack.mdMDI: Kerberos/NTLM brute-force, Golden Ticket, pass-the-ticket, LDAP/SAMR recon
Suspected Golden Ticketmdi-identity-attack.md
Suspected identity theft (pass-the-ticket)mdi-identity-attack.md
Security principal reconnaissance (LDAP)mdi-identity-attack.md
User and group membership reconnaissance (SAMR)mdi-identity-attack.md
Suspicious OAuth appoauth-app-abuse.mdOAuth app abuse, credential additions, unknown ISP
Unusual addition of credentials to an OAuth appoauth-app-abuse.md
Unusual ISP for an OAuth Appoauth-app-abuse.md
OAuth application activity from an unknown ISPoauth-app-abuse.md
App is similar to previously flagged suspicious appsoauth-app-abuse.md
App metadata associated with known phishing campaignoauth-app-abuse.md
Increase in data usage by an overprivilegedoauth-app-abuse.md
Salesforce Connected Application activityoauth-app-abuse.md
Addition to Exchange Organization Managementprivilege-escalation.mdPrivilege escalation — role/group changes, suspicious admin activity
Suspicious additions to sensitive groupsprivilege-escalation.md
Suspicious addition and removal of elevated privilegesprivilege-escalation.md
Suspicious administrative activityprivilege-escalation.md
Administrative action submitted by an Administratorprivilege-escalation.md