Knowledge base / Playbooks
Playbooks Short, decision-oriented response plans designed to be used under pressure, with owners, evidence, containment, and exit criteria.
12 articles · source-backed · editorially reviewed
Guide PLAYBOOKS
10 Sept 2026 · 15 min read · Intermediate
An administrative Windows password reset can restore sign-in while breaking access to DPAPI-protected secrets, EFS files and private keys. Learn how to identify the account type, preserve a working session, back up recovery material and prove the data still opens.
Windows DPAPI EFS Password Recovery Windows 11 Active Directory Microsoft Entra ID Windows Hello Sysadmin
Read article →
Guide PLAYBOOKS
5 Sept 2026 · 7 min read · Intermediate
Combine code review, safe staging tests, structured application events, web telemetry and endpoint evidence to find injection flaws and investigate attempted exploitation.
Data injection Detection engineering OWASP ZAP SAST Incident response
Read article →
Guide PLAYBOOKS
13 Aug 2026 · 11 min read · Advanced
A role-based cloud identity response checklist from declaration through session revocation, evidence, persistence review, lockout recovery, and monitoring.
Microsoft Graph PowerShell Exchange Online PowerShell
Read article →
Guide PLAYBOOKS
7 Aug 2026 · 8 min read · Advanced
Coordinate business continuity, isolation, evidence, identity protection, external obligations, and clean recovery.
find PowerShell SMB cmdlets restic
Read article →
Guide PLAYBOOKS
1 Aug 2026 · 9 min read · Intermediate
Triage the message, interaction, identity, endpoint, and recipient scope without detonating the lure or deleting the only evidence.
grep Python standard library
Read article →
Guide PLAYBOOKS
26 Jul 2026 · 8 min read · Advanced
Capture the application and grant, disable access, find affected data and users, and prevent the same consent path from recurring.
Microsoft Graph PowerShell
Read article →
Guide PLAYBOOKS
20 Jul 2026 · 8 min read · Beginner
Use device state, encryption, data classification, identity, remote management, and legal requirements to choose proportionate action.
BitLocker PowerShell Microsoft Graph PowerShell PowerShell and Windows Event Log
Read article →
Guide PLAYBOOKS
14 Jul 2026 · 8 min read · Intermediate
Replace and revoke the secret, but also establish exposure time, permissions, use, copies, dependencies, and newly created persistence.
Git Shell Provider API client
Read article →
Guide PLAYBOOKS
8 Jul 2026 · 8 min read · Advanced
Protect availability while preserving web, identity, process, file, network, deployment, and cloud evidence.
ps, ss and login tools journalctl and find curl
Read article →
Guide PLAYBOOKS
2 Jul 2026 · 8 min read · Intermediate
Separate malicious traffic, flash demand, dependency failure, and capacity exhaustion while keeping communication and evidence intact.
ss or PowerShell logger and central search Node.js fetch
Read article →
Guide PLAYBOOKS
26 Jun 2026 · 8 min read · Advanced
Coordinate legal, HR, privacy, identity, endpoint, and data evidence without tipping off the subject or exceeding authorised monitoring.
Built-in shell tools Application logger osqueryi
Read article →
Guide PLAYBOOKS
20 Jun 2026 · 8 min read · Intermediate
Turn a supplier notification into an inventory, access, data, continuity, and evidence response for your own organisation.
Trivy Git
Read article →