
A field-tested incident response playbook for SOC analysts, responders, and application security engineers who handle attacks against web apps, APIs, and public infrastructure.
Who it’s for
SOC analysts, blue-teamers, and IT/security teams who need a written workflow when a web intrusion is in progress — not a coaching program and not a live community.
The problem it solves
Web incidents get improvised. This playbook gives you the sequence: triage, contain, investigate, eradicate, and report — with checklists, SIEM queries, and a Notion template you can duplicate.
What’s included
• Full IR lifecycle: triage, containment, forensics, eradication, post-incident reporting
• Scenario checklists: web shells, SQL injection with data theft, reflected XSS session hijacking
• SIEM and hunting queries for Splunk, Microsoft Sentinel (KQL), and MySQL audit logs
• Mapping to NIST IR phases and MITRE ATT&CK
• Forensic artifact notes for Linux (Nginx/Apache), Windows (IIS), and containers
• Notion template (duplicate into your workspace)
• Incident report template (executive and technical)
How it works
One-time payment. Instant access. Does not guarantee a job, interview, or incident outcome. Practice only on systems you own or are authorized to handle.