> For the complete documentation index, see [llms.txt](https://docs.inopli.com/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.inopli.com/response/rules/playbooks.md).

# Playbooks

The dashboard integrates with the correlation rules, providing management of responses to security incidents. Through a paginated list, the <mark style="color:green;">dashboard allows for the addition, editing, deletion, and activation of playbooks in an intuitive and organized manner.</mark>

The ability to activate or deactivate playbooks as needed ensures that responses to incidents are prompt.

<figure><img src="https://2621223932-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FLTQJomzpe5BTzHSLQPAt%2Fuploads%2FFtn40RnZXN5nzz9xTx9q%2FScreenshot%202023-12-30%20at%2014.41.13.png?alt=media&amp;token=eb250bed-b409-4538-8303-8021a6e13357" alt=""><figcaption><p>Overview Playbooks Dashboard</p></figcaption></figure>

***

## Creating a Playbook

### Identification

* **Nome:** Must be <mark style="color:green;">descriptive, clearly</mark> reflecting the purpose and scope of the playbook.
* **Visibilidade:**&#x20;
  1. **DEFAULT:** This category includes <mark style="color:green;">general use playbooks</mark>. They are designed to be applicable in a wide range of scenarios and companies.
  2. **ADVANCED:** Playbooks in this category are <mark style="color:green;">customized for the specific needs of a company</mark>. They are detailed and focused on particular scenarios, reflecting the policies, infrastructure, and specific security risks of the company.

<figure><img src="https://2621223932-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FLTQJomzpe5BTzHSLQPAt%2Fuploads%2F1FKRhUHMBKCmSA3EVXtS%2FScreenshot%202023-12-30%20at%2014.43.19.png?alt=media&amp;token=e7172801-9cfa-4d7f-841e-5f059d127e6f" alt=""><figcaption><p>Identification Stage</p></figcaption></figure>

***

### Phases of Incident Response

<mark style="color:green;">It is possible to manage treatment steps for each of the incident response phases</mark>, as outlined by the most renowned market frameworks, with the possibility of assigning the responsibility of the stage to the MSP or the company.&#x20;

The stages are:&#x20;

1. **Preparation:** <mark style="color:green;">Prepare the incident response team</mark> to efficiently deal with potential threats. (E.g., Team training, creation and updating of documentation).&#x20;
2. **Identification:** The first active response stage, where the <mark style="color:green;">veracity of the incident is determined</mark>. Detailed analysis to confirm whether the incident is a false positive or a real threat.&#x20;
3. **Containment:** Implemented only if the incident is confirmed. Execute <mark style="color:green;">measures to prevent the spread of the threat</mark> (e.g., isolation of systems or network segmentation).&#x20;
4. **Eradication:** <mark style="color:green;">Identify and eliminate the root cause of the incident</mark> (e.g., Removal of malware, correction of vulnerabilities, and strengthening of security controls).&#x20;
5. **Recovery:** Take the necessary <mark style="color:green;">measures to return the environment to normal operation</mark> (e.g., Verification of system integrity, data restoration from backups, and post-recovery monitoring).

<figure><img src="https://2621223932-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FLTQJomzpe5BTzHSLQPAt%2Fuploads%2FdRZMf9P4YyEJoYWYdLZJ%2FScreenshot%202023-12-30%20at%2014.58.33.png?alt=media&amp;token=eeb23f23-c3c9-4ca4-9b83-1a1456757b3a" alt=""><figcaption><p>Phase of Incident Response Example</p></figcaption></figure>

***

### Lessons Learned

Reserved space <mark style="color:green;">to describe strategies in the post-incident analysis to identify improvements</mark> in the playbook and security practices.

<figure><img src="https://2621223932-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FLTQJomzpe5BTzHSLQPAt%2Fuploads%2FKb8gCz1BMJVSrNdjcacv%2FScreenshot%202023-12-30%20at%2015.04.31.png?alt=media&amp;token=607bef25-25a2-4a59-935a-47ea9b338ad6" alt=""><figcaption><p>Lessons Learned Stage</p></figcaption></figure>

***

### Comments

Space for the security team <mark style="color:green;">to leave notes and important observations about the playbook.</mark>

<figure><img src="https://2621223932-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FLTQJomzpe5BTzHSLQPAt%2Fuploads%2Fa4TIq6EAG3EVo7F1LMc7%2FScreenshot%202023-12-30%20at%2015.03.58.png?alt=media&amp;token=abe2ec0a-aea3-43fe-a9a7-de06f9af06cc" alt=""><figcaption><p>Comments Stage</p></figcaption></figure>

***

### Versioning

Space to <mark style="color:green;">document the revision with each update of the playbook</mark>, providing a detailed history and an audit trail.

{% hint style="danger" %}
Whenever the playbook is updated, it is necessary to provide a description of the new version.
{% endhint %}

<figure><img src="https://2621223932-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FLTQJomzpe5BTzHSLQPAt%2Fuploads%2F0RO7pGgat8D4uwK8kqNq%2FScreenshot%202023-12-30%20at%2015.04.43.png?alt=media&amp;token=8b6abb02-cbf7-44b6-81bd-d40f1e9f4088" alt=""><figcaption><p>Versioning Stage</p></figcaption></figure>

***
