Applied Playbooks

Threat-specific packages built on five OODA loops. Each includes free afternoon deploys, core engagement scope, and target-state architecture.

16
Playbooks
5
OODA Loops
80+
Free Tools
3
Tiers
These playbooks apply two capability frameworks to specific threat domains: Detection Engineering for finding threats, and Investigation Automation for understanding them. See the full methodology →

Defense Architecture

Five OODA Loops

Security has not one but five distinct decision loops, each with different cycle times. The fastest loop protects the slower loops. Every playbook below is structured around these five loops.

Defense Architecture
Five OODA Loops
The fastest loop protects the slower loops.
Each layer is a decision cycle with its own tempo.
05Structural
weeks – months
CONSULT
04Vulnerability Management
hours – days
HUNT
03Posture / Drift
continuous
COG-SOC
02Detection & Response
minutes – hours
COG-SOC
01Containment
minutes
COG-SOC
Loop 0 — Hard Barriers  •  Immutable Backups  •  Segmentation  •  Identity Hardening
The operating model behind the five loops: why security is an immune system, not an ambulance — the prevention-first thesis, the hospital metaphor, and how the loops protect each other. Read the operating model →

Respond

Incident Response Playbooks

It is happening now. Timed steps with the reason for each, a "How far has it got?" question list for triage, and a matching TheHive case template. Everything below this section is how you get ready.

IR Playbook

Ransomware Response

The first 72 hours, by scenario: encryption in progress, discovered before encryption, data theft without encryption, hypervisor/NAS, backups destroyed, cloud data held hostage. Isolate, don't power off; protect the way back; the board's pay/don't-pay facts.

6 scenarios • 3 progression ladders • 4 case templates
IR Playbook

BEC Response

Compromised mailbox, payment in flight. Money first, then mailbox: bank recall, capture-then-purge rules, tenant sweep, and who to warn.

60-minute target • payment recall first
IR Playbook

Identity Breach Response

You're already compromised — what to do in the next 15 minutes, 4 hours, 30 days. T+0 containment commands, 8 incident-type variations (account takeover, device-code, OAuth abuse, NHI, privileged). Password reset is not remediation.

Active IR • 15-min containment window • 8 incident variations
IR Playbook

Device Code Abuse Response

Device-code phishing confirmed or suspected. The 12-step containment checklist: revoke before reset, kill device registrations, audit OAuth consent, hunt tenant-wide.

12 steps • revoke before reset
IR Playbook

Supply Chain Incident Response

A vendor disclosed a breach, or a package or update you install shipped malicious code. Vendor track: validate, suspend data flows, revoke every credential they hold. Package track: find everywhere it was installed, pin, and rotate every secret it could read.

Vendor breach • compromised npm / PyPI / Actions / vendor update
IR Playbook

Cloud Incident Response

An attacker in AWS, Azure or GCP. Keep the logs running, revoke the credential and the sessions it already minted, quarantine the account when the scope is unknown, and hunt every key, role and trust they created. Leaked keys, cryptomining, storage theft or hostage, compromised workloads and pipelines, root or tenant admin.

7 scenarios • 10-stage progression • AWS / Azure / GCP
IR Playbook

ClickFix Response

A user pasted a fake-CAPTCHA command. Isolate, capture the command from RunMRU or the PowerShell history, revoke every session the stealer took, and decide whether it is a stealer or a foothold.

Win+X / Terminal • Win+R • download-folder staging

Prevent — Loop 0

The Foundation: Hard Barriers

Before any threat-specific playbook, these three controls must be in place. They are chosen for one property: each one refuses the attacker's action rather than slowing it down. That is the doctrine for Loop 0 — invest in hard barriers first, treat friction as a bonus.

The barrier test. Ask of every control: can an attacker get past it with more attempts, more time or more patience? Then it is friction. Does it refuse the action outright, so the attacker needs a specific bypass that doesn't exist by default? Then it is a hard barrier.
Friction — slows the attackerHard barrier — refuses the attacker
Non-standard ports, renamed Administrator, hidden bannersDefault-deny firewall rules between zones: workstations cannot reach domain-controller admin ports
TOTP codes and push approvals — phishable, they add effortFIDO2 / passkeys — the key will not sign for a lookalike domain
Backups that are hidden, or "hard to find" on the networkWORM / Object Lock storage with separate backup credentials — deletion is refused, not delayed
Rate limits, CAPTCHAs, lockout thresholds, code obfuscationMemory protections (W^X, KASLR) and memory-safe languages that remove a bug class
Why this matters more now. Anthropic's Frontier Red Team, assessing Claude Mythos Preview (April 2026): “Mitigations whose security value comes primarily from friction rather than hard barriers may become considerably weaker against model-assisted adversaries. Defense-in-depth techniques that impose hard barriers (like KASLR or W^X) remain an important hardening technique.” Models grind through tedious steps quickly and at scale, which is exactly what friction relies on attackers not doing. Two caveats: this is Anthropic's stated expectation, not a measured result, and the same assessment reports Mythos producing KASLR bypasses — hard barriers force the attacker to chain more exploits, they are not unbreakable. The mapping of segmentation, FIDO2 and WORM backups onto the barrier column is our application of the principle, not Anthropic's.
Loop 0 — Hard Barrier

Immutable Backups

3-2-1-1 architecture, WORM storage, tested restores. The control that makes ransomware a recoverable event, not an existential one. Includes backup kill chain analysis and management AD architecture.

The barrier: the storage layer refuses deletion, even for an admin. Hidden or obscure backups are only friction.

94% of ransomware targets backups • 57% succeed
Loop 0 — Hard Barrier

Network Segmentation

3-4 VLANs minimum. Workstations, servers, backup infrastructure, management. Default deny between zones. The compensating control when you can't patch fast enough — limits blast radius to one segment.

The barrier: a deny rule leaves nothing to grind through, only a different path to find. VLANs without enforced rules between them are friction.

Cross-cutting control • Referenced in every playbook
Loop 0 — Hard Barrier

Identity Hardening

MFA everywhere. FIDO2 for admins. Separate admin accounts. LAPS for local admin. Block legacy auth. 56% of breaches start with stolen credentials — this is where you stop them.

The barrier: phishing-resistant FIDO2 and blocked legacy auth. TOTP and push MFA are friction — better than nothing, but phishable.

56% of initial access via stolen creds

Prevent — Threat Domains

Threat-Specific Playbooks

Each playbook addresses a specific threat across all five OODA loops, with free afternoon deploys, core consulting engagements, and target-state architecture. The matching response playbooks are under Respond above.

Email Threat

BEC Defense

Email Resilience Program. Universal impersonation protection with silent quarantine, FIDO2, browser isolation, CDR, behavioral AI. The four-layer stack that breaks attacker economics.

$2.77B FBI losses • 81% of investigated incidents • 13 free controls
Identity

Identity Hardening

Defense in depth for the identity layer itself. FIDO2 universal, Conditional Access architecture, token discipline, OAuth consent posture, NHI program. Closes six branches of the identity attack tree.

79% MFA bypass rate • 6 attack branches • 13 free controls
Identity

Device Code Abuse

M365 / Entra ID runbook for Storm-2372 / EvilTokens / FlowerStorm class attacks. MFA does not stop this — the victim authenticates to a real Microsoft page. One Conditional Access policy closes the door; eight Sentinel hunts find the cases that slip through.

1 CA policy • 8 KQL alert rules • Config-only, no licensing
Ransomware

Ransomware Resilience

Recovery Without Paying. Patterson Cake containment playbooks (Kill Internet + Kill Authentication), immutable backups, EDR, segmentation. Insurance readiness checklist.

$613K avg demand • 88% encrypt outside hours • 12 free controls
Supply Chain

Supply Chain Security

Your Vendors Are Your Attack Surface. MSP access hardening, OAuth lockdown, SaaS sprawl discovery. NIS2 Article 21(d) compliance.

73% YoY increase • 200-400 SaaS apps avg • MSP 10-point checklist
Cloud

Cloud Security

Four Things That Matter: Auth, Keys, Permissions, Exposure. IP-bound API keys, managed identities, least privilege, public access prevention. Big 3 + mid-market provider guidance.

82% incidents = misconfig • 95% customer's fault • $49 scanning stack
Initial Access

ClickFix

Fake-CAPTCHA Initial Access — Detection & Prevention. Win+R is largely obsolete; Win+X now dominates (~90%). Per-visitor unique payloads defeat YARA. Covers runspace hunting, RunMRU detection, download-folder correlation, AppLocker + WDAC script enforcement, and fake CAPTCHA awareness training.

517% increase into 2025 • ~90% via Win+X • ~80% deliver infostealers
Threat Intel

Regional Sector Targeting

Who Gets Hit, by Region — a cross-vendor synthesis of the most-targeted sectors across Benelux, DACH, UK & the Nordics. De-biased across 16+ vendor & CERT sources, with the methodology caveat front and centre: each region is measured with a different ruler.

16+ sources • 4 regions • Mfg #1 in 3 of 4

Prevent — Posture & Operations

Posture & Operations Playbooks

Posture

Configuration Drift

Stop Defending What You've Already Disabled. Shift down, not shift left — wire security into the platform so teams get it for free. Configuration-as-code for M365. Breach-forensic-driven priority list.

99% of firewall breaches = misconfig • 10,000+ M365 settings
Operations

VM & Patching

Easy vs Hard. CISA KEV + EPSS prioritization replaces CVSS score chasing. Edge devices first (44% of zero-days). Auto-update what you can, segment what you can't.

5-day TTE vs 55-day patch time • 2.3% of CVSSs exploited
Infrastructure

Log Management

Keep data for the need, not the architecture. Four copies already exist — on-host, cloud native, backup, SIEM. Right-size your SIEM for detection (30–90d), not storage. €50–150/month vs €10K enterprise.

4 copies already exist • 80/20 log source rule • Wazuh = free
Posture

Windows LOLBIN Hardening

Cut Living-Off-The-Land execution. ACL DENY for SYSTEM as a stopgap, then WDAC application control for the durable answer. Renamed binaries and dropped copies don't bypass. Ships three working artifacts — deny script, WDAC supplemental, build+deploy pipeline.

62% of intrusions use built-in tools • 190+ LOLBAS binaries • 12 free controls
Operations

MDR Detection Maturity

Detection at scale, prerequisites, and the five-level maturity ladder. For MDR builders, buyers evaluating vendors, and SOC leaders making the build-vs-partner call. Three-tier model, six detection sources, RFP question set.

70/25/5 rule mix • <24h TTP-to-fleet target • 5 maturity levels

All Playbooks at a Glance

PlaybookThreat / DomainDurationInvestment (200 seats)Free Controls
Immutable BackupsFoundation (Loop 0)9–11 days€11,250 – 13,7506
BEC DefenseEmail / Identity10–15 days€12,500 – 18,75013
Identity HardeningIdentity / Prevention10–15 days€12,500 – 18,75013
Identity Breach ResponseActive IR — Identity2–5 days (IR assist)€5,000 – 12,500n/a (IR)
Device Code AbuseIdentity / Detection & Response3–5 days€3,750 – 6,2509 (1 CA + 8 KQL)
Ransomware ResilienceRansomware / Recovery12–17 days€15,000 – 21,25012
Supply Chain SecurityThird-Party / Vendor9–13 days€11,250 – 16,2507
Cloud SecurityCloud / IaaS / SaaS11–16 days€13,750 – 20,00012
Configuration DriftPosture / Compliance10–15 days€12,500 – 18,75010
VM & PatchingVulnerabilities / Patching10–15 days€12,500 – 18,75012
Log ManagementLogging / Detection Infra6–8 days€7,500 – 10,0004
Windows LOLBIN HardeningPosture / Endpoint Hardening11–17 days€13,750 – 20,00012
MDR Detection MaturityOperations / Detection Eng3–10 days€3,750 – 12,500n/a (assess)
AI Agent SecurityAI Governance / NIS212–19 days€15,000 – 23,75011
ClickFixInitial Access / Endpoint4–7 days€5,000 – 8,7508
Regional Sector TargetingThreat Intel / ReferenceReferencen/a (intel)n/a
Start with the self-assessment. Run the free browser-based assessment to see where you stand, then every playbook begins with a 1–2 day expert assessment (€1,250–2,500) that scores your maturity across all five loops and hands over free quick wins immediately.

AI SecOps

AI SecOps

Beyond playbooks: helping security teams build, test, and govern their own AI agents.

Governance

AI Agent Security

Govern the Machines Before They Govern You. Data safety levels (Block's CDC model), agent identity attribution, prompt injection defense, MCP governance. Five OODA loops from inventory through detection. NIS2 Article 21 compliance mapping included.

40% AI-assisted detections at Block • 8% malicious MCP repos • 11 free controls
Architecture

The Context Layer

Six architectural approaches to the contextual-triage layer — vector memory, entity graph, data lake, bespoke ML, full context graph, hybrid — scored on five dimensions (temporality, provenance, semantics, governance, decision trace). The conclusion is hybrid: no single substrate wins.

5 dimensions • 6 approaches • 0 single-substrate winners