Free incident response plan template based on NIST SP 800-61. Includes playbooks for ransomware, phishing, data breach, and BEC.
-
Updated
Mar 2, 2026
Free incident response plan template based on NIST SP 800-61. Includes playbooks for ransomware, phishing, data breach, and BEC.
🚨 Full NIST 800-61 incident response against a multi-stage SSH intrusion - IR plan, playbook, live SIEM detection, containment, eradication, and after-action report with metrics and MITRE ATT&CK mapping.
Enterprise incident response playbooks aligned with NIST SP 800-61 and SANS IR framework with MITRE ATT&CK mappings
Standardized incident response procedures, playbooks, and runbooks for SOC teams protecting critical infrastructure
I-powered SIEM alert triage tool — MITRE ATT&CK mapping, IOC extraction, false positive reduction, and investigation playbooks using Claude AI
Building a Microsoft Sentinel detection rule for impossible travel sign-in activity using Azure SigninLogs and KQL. Investigating user logon geography and working the incident to closure under NIST SP 800-61.
Building a Microsoft Sentinel detection rule for suspicious PowerShell web requests (Invoke-WebRequest) and working the incident to closure using the NIST 800-61 lifecycle. KQL analytics rule, entity mapping, and execution verification.
NIST 800-61–aligned runbooks for cloud credential compromise, business email compromise, ransomware, and data exfiltration.
Building a brute force detection rule in Microsoft Sentinel and working the resulting incident to closure using the NIST 800-61 lifecycle. KQL analytics rule, entity mapping, and NSG containment.
Hands-on incident response simulation lab — blue team procedures, SOC workflows, Salt Typhoon APT research, and DR failover documentation
AI-powered Incident Response Plan engine for MSPs — NIST 800-61 aligned playbooks, BYOM (Anthropic/OpenAI/Gemini/Ollama), ConnectWise + N8N integration, 2,000-incident scenario corpus + 60 tests
SOC incident response playbooks and case studies for phishing, malware, and insider threat scenarios. Aligned to NIST SP 800-61 Rev. 2.
Cross-framework Incident Response Playbook Library — ISO/IEC 27035:2016 + NIST SP 800-61 r2 (CSF 2.0).
Strategic cybersecurity governance repository featuring a hybrid Incident Response Plan (IRP) integrating NIST SP 800-61 Rev. 2 and SANS methodologies. Includes modernized forensic forms, chain of custody protocols, and policy analysis.
Building a Microsoft Sentinel detection rule for excessive Azure resource creation and deletion using the AzureActivity log and KQL. Triaging caller activity and working the incident to closure under NIST SP 800-61.
Add a description, image, and links to the nist-800-61 topic page so that developers can more easily learn about it.
To associate your repository with the nist-800-61 topic, visit your repo's landing page and select "manage topics."