Topic hub
Incident response
Definition
Incident response — is the structured process an organization follows to detect, contain, eradicate and recover from a cyber attack, and to establish how the attacker got in and what they accessed.
Containment is not the finish line. Isolating the host that tripped the alert stops the symptom you can see; it does not tell you which credentials were taken, what else was touched, or whether the access that let the attacker in is still open. This hub collects what we have published on running an incident to a real conclusion.
The phases of an incident response engagement
A complete engagement runs six phases: preparation, identification, containment, eradication, recovery and lessons learned. Preparation happens before anything goes wrong — it is the readiness work that decides how fast the other five can run. Identification establishes that an incident is real and what its scope is. Containment stops the spread without destroying the evidence needed to understand it. Eradication removes the attacker and closes the access path. Recovery restores operations and verifies the environment is genuinely clean. Lessons learned turns the incident into changes that prevent a repeat.
What to do in the first hour
The decisions taken in the first hour determine how much of the incident can ever be reconstructed. Do not power off affected machines — shutting down destroys memory, which is frequently the only place evidence of the attack exists. Do not rebuild or reimage before evidence is captured. Do preserve systems in place, disconnect from the network if lateral movement is a live risk, start a written timeline of what you observe and when, and contact responders before remediating. The full do/do-not checklist is on our under attack page.
Why incidents recur
An incident closed at the symptom is the one that comes back. When the root cause is never established — the initial access vector, the credential that was stolen, the persistence mechanism that survived the cleanup — the same actor returns through the same door, and the second intrusion is usually quieter than the first.
Open-source tooling
M365 forensics
MAES
The M365 Analyzer & Extractor Suite — extract, analyze and preserve evidence from Microsoft 365 tenants with SHA-256 chain of custody.
Fortinet forensics
Forti-DFIR
Open-source framework giving security teams the tooling they need for forensic investigations and incident response in Fortinet environments.
Prevention
RansomProtect
Detects and blocks ransomware and wipers early in the infection chain, where built-in OS defenses fall short.
Evidence capture
DO Audit Log Scraper
Chrome/Chromium extension enabling forensic-grade audit log extraction. Now at v2.0.
Everything we have published on incident response
16 pieces of research, tooling and case-study work.
Common questions
What is incident response?
Incident response is the structured process an organization follows to detect, contain, eradicate and recover from a cyber attack, and to establish how the attacker got in and what they accessed. A complete response does not stop at isolating the affected system: it reconstructs the full attack chain, because an incident closed at the symptom is the one that recurs.
What are the phases of incident response?
The six phases of incident response are preparation, identification, containment, eradication, recovery, and lessons learned. Preparation happens before an incident and determines how quickly the remaining five can run; lessons learned closes the loop by turning the incident into changes that prevent a repeat.
What should you do first if you have been breached?
Contact an incident response team before you start remediating, and preserve the affected systems in place. Rebuilding, reimaging or powering off a compromised machine destroys the volatile evidence needed to establish how far the attacker got and what they took.
Should you shut down a computer that has been hacked?
No — powering off a compromised machine destroys the contents of memory, which is often the only place evidence of the attack exists. Disconnecting it from the network to stop lateral movement is usually the safer action, but confirm with your responders first, because some malware reacts to losing connectivity.
How fast should an incident response team respond?
Response time should be measured from first contact to the start of investigative work, not to an acknowledgement email. IONSEC commits to an assured four-hour response from first contact, 24 hours a day, every day of the year, with forensic acquisition and volatile-memory capture performed remotely.
What is the difference between incident response and disaster recovery?
Incident response deals with an adversary: it establishes what an attacker did, removes them, and closes the path they used. Disaster recovery deals with restoring service after an outage, whatever its cause. Restoring from backup without an incident response process risks restoring the attacker along with the data.
How we help
Emergency Incident Response
24/7 emergency incident response with an assured four-hour response from first contact — containment, full attack-chain reconstruction, and guided recovery.
Cyber Preparedness
Map your IT, OT and IoT estate, close the visibility gaps an investigation depends on, and rehearse your incident response before you need it.
Related topics
Digital forensics (DFIR)
Digital forensics and incident response (DFIR) is the combined discipline of collecting and analysing digital evidence to establish what happened during a cyber attack, and managing that attack end to end.
Cyber research
Cyber threat research is the systematic investigation of adversary tooling, infrastructure and behaviour — malware analysis, campaign attribution and technique documentation — carried out to make the resulting knowledge usable in defence.
Talk to the team that does the work
The people who publish the research above are the people who take your escalations.