Skip to content
Open

Large diffs are not rendered by default.

Original file line number Diff line number Diff line change
Expand Up @@ -14,6 +14,7 @@ title: "Runbooks"
- [Runbooks](/incident-management/incident-response-template/runbooks/overview)
- [Runbook: Smart Contract Exploit](/incident-management/incident-response-template/runbooks/smart-contract-exploit)
- [Runbook: Key Compromise](/incident-management/incident-response-template/runbooks/key-compromise)
- [Runbook: Endpoint Compromise](/incident-management/incident-response-template/runbooks/endpoint-compromise)
- [Runbook: Frontend Compromise](/incident-management/incident-response-template/runbooks/frontend-compromise)
- [Runbook: DNS Hijack](/incident-management/incident-response-template/runbooks/dns-hijack)
- [Runbook: CDN/Hosting Compromise](/incident-management/incident-response-template/runbooks/cdn-hosting-compromise)
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -40,15 +40,17 @@ ensure consistent response.
active exploit or critical vulnerability.
2. [Key Compromise](/incident-management/incident-response-template/runbooks/key-compromise): private
key or signer compromise.
3. [Frontend Compromise](/incident-management/incident-response-template/runbooks/frontend-compromise):
3. [Endpoint Compromise](/incident-management/incident-response-template/runbooks/endpoint-compromise):
contributor workstation compromise; severity follows the access tier the user holds.
4. [Frontend Compromise](/incident-management/incident-response-template/runbooks/frontend-compromise):
website/UI compromise (routes to specialized runbooks below).
4. [DNS Hijack](/incident-management/incident-response-template/runbooks/dns-hijack): domain/DNS
5. [DNS Hijack](/incident-management/incident-response-template/runbooks/dns-hijack): domain/DNS
compromise.
5. [CDN/Hosting Compromise](/incident-management/incident-response-template/runbooks/cdn-hosting-compromise):
6. [CDN/Hosting Compromise](/incident-management/incident-response-template/runbooks/cdn-hosting-compromise):
CDN or hosting provider compromise.
6. [Dependency Attack](/incident-management/incident-response-template/runbooks/dependency-attack):
7. [Dependency Attack](/incident-management/incident-response-template/runbooks/dependency-attack):
npm/package supply chain attack.
7. [Build Pipeline Compromise](/incident-management/incident-response-template/runbooks/build-pipeline-compromise):
8. [Build Pipeline Compromise](/incident-management/incident-response-template/runbooks/build-pipeline-compromise):
CI/CD compromise.

### High/Moderate (P2-P3)
Expand Down
2 changes: 2 additions & 0 deletions docs/pages/incident-management/playbooks/hacked-dprk.mdx
Original file line number Diff line number Diff line change
Expand Up @@ -94,6 +94,8 @@ file you were expecting, so that you do not suspect you were infected.
- [Playbooks overview](/incident-management/playbooks/overview): how the playbooks in this section fit together
- [DPRK IT Workers](/dprk-it-workers/overview): who the actor is and how they get hired
- [Mitigating DPRK IT Workers](/dprk-it-workers/mitigating-dprk-it-workers): hardening and post-discovery steps
- [Endpoint Compromise runbook](/incident-management/incident-response-template/runbooks/endpoint-compromise):
what the security team runs if this reached a contributor's machine
- [SEAL 911 War Room Guidelines](/incident-management/playbooks/seal-911-war-room-guidelines): reaching outside help fast

---
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -81,6 +81,8 @@ accounts and sending out phishing messages to more people.
- [Playbooks overview](/incident-management/playbooks/overview): how the playbooks in this section fit together
- [Zoom Hardening](/guides/endpoint-security/zoom-hardening): closing the vector this attack uses
- [Malware playbook](/incident-management/playbooks/malware): response once code has run on the device
- [Endpoint Compromise runbook](/incident-management/incident-response-template/runbooks/endpoint-compromise):
what the security team runs if this reached a contributor's machine
- [SEAL 911 War Room Guidelines](/incident-management/playbooks/seal-911-war-room-guidelines): reaching outside help fast

---
Expand Down
2 changes: 2 additions & 0 deletions docs/pages/incident-management/playbooks/malware.mdx
Original file line number Diff line number Diff line change
Expand Up @@ -185,6 +185,8 @@ Here are some guides specifically for securing your:
## Further reading

- [Playbooks overview](/incident-management/playbooks/overview): how the playbooks in this section fit together
- [Endpoint Compromise runbook](/incident-management/incident-response-template/runbooks/endpoint-compromise):
the responder-side process if this happened to a colleague
- [Endpoint Security](/opsec/endpoint/overview): device hardening that limits the blast radius
- [Drainer playbook](/incident-management/playbooks/hacked-drainer): response if wallet access followed
- [SEAL 911 War Room Guidelines](/incident-management/playbooks/seal-911-war-room-guidelines): reaching outside help fast
Expand Down
1 change: 1 addition & 0 deletions vocs.config.ts
Original file line number Diff line number Diff line change
Expand Up @@ -293,6 +293,7 @@ const config = {
{ text: 'Overview', link: '/incident-management/incident-response-template/runbooks/overview' },
{ text: 'Smart Contract Exploit', link: '/incident-management/incident-response-template/runbooks/smart-contract-exploit' },
{ text: 'Key Compromise', link: '/incident-management/incident-response-template/runbooks/key-compromise' },
{ text: 'Endpoint Compromise', link: '/incident-management/incident-response-template/runbooks/endpoint-compromise' },
{ text: 'Frontend Compromise', link: '/incident-management/incident-response-template/runbooks/frontend-compromise' },
{ text: 'DNS Hijack', link: '/incident-management/incident-response-template/runbooks/dns-hijack' },
{ text: 'CDN/Hosting Compromise', link: '/incident-management/incident-response-template/runbooks/cdn-hosting-compromise' },
Expand Down
Loading