product image

SOC Web App IR Playbook

$9.99

Incident response workflows for web and API attacks.

A field-tested incident response playbook for SOC analysts, responders, and application security engineers who handle attacks against web apps, APIs, and public infrastructure.

Who it’s for
SOC analysts, blue-teamers, and IT/security teams who need a written workflow when a web intrusion is in progress — not a coaching program and not a live community.

The problem it solves
Web incidents get improvised. This playbook gives you the sequence: triage, contain, investigate, eradicate, and report — with checklists, SIEM queries, and a Notion template you can duplicate.

What’s included
• Full IR lifecycle: triage, containment, forensics, eradication, post-incident reporting
• Scenario checklists: web shells, SQL injection with data theft, reflected XSS session hijacking
• SIEM and hunting queries for Splunk, Microsoft Sentinel (KQL), and MySQL audit logs
• Mapping to NIST IR phases and MITRE ATT&CK
• Forensic artifact notes for Linux (Nginx/Apache), Windows (IIS), and containers
• Notion template (duplicate into your workspace)
• Incident report template (executive and technical)

How it works

  1. Buy once. Open the Access post in your membership.
  2. Duplicate the Notion template into your workspace.
  3. Run the playbook against the scenario in front of you.

One-time payment. Instant access. Does not guarantee a job, interview, or incident outcome. Practice only on systems you own or are authorized to handle.