SANS Incident Handler's Handbook and PICERL Methodology
Evidence request list. 40 controls, 40 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 12 September 2026. Published by The Art of Service.
Containment
Apply short term containment such as network segmentation, host isolation, account disablement, or traffic blocking to stop ongoing damage while preserving evidence.
- Containment decision log
- Isolation evidence such as switchport configs and EDR actions
- Account disablement records
- Block list updates
- Containment delayed by change control
- Wiping host before evidence collected
- Account disabled but session tokens remain valid
Capture forensic images and volatile memory of compromised systems before applying remediation steps, with hashed and stored evidence for later analysis.
- Memory and disk image acquisitions
- Hash logs
- Storage manifest
- Imaging tool version log
- Memory not captured before reboot
- Imaging skipped under time pressure
- Storage location not encrypted
Implement long term containment for systems that cannot be immediately rebuilt, including hardening, monitoring uplift, and temporary workarounds maintained until eradication.
- Hardening checklist applied
- Enhanced monitoring deployment
- Workaround risk acceptance
- Exit criteria
- Workarounds become permanent
- Monitoring uplift removed too early
- Risk acceptance not approved at correct level
Eradication
Identify and document root causes including initial access vector, persistence mechanisms, lateral movement paths, and control failures, before applying eradication actions.
- Root cause analysis report
- Kill chain mapping
- Control failure analysis
- Persistence enumeration evidence
- RCA limited to malware names without control gaps
- Lateral movement under analysed
- Persistence not enumerated across all hosts
Remove threat actor artefacts including malware, web shells, accounts, scheduled tasks, services, and persistence mechanisms across all affected systems prior to recovery.
- Eradication checklist by asset
- Persistence sweep results
- Account audit
- Verification scan results
- Web shells missed in non-standard directories
- Cloud persistence not enumerated
- Service accounts created by actor remain
Reset credentials, rotate secrets, invalidate sessions and tokens, and review identity infrastructure for trust abuse such as golden ticket or federation tampering.
- Credential reset records
- Token invalidation evidence
- KRBTGT reset log where applicable
- Federation trust review
- Service account secrets not rotated
- Mobile and refresh tokens not invalidated
- Federation tampering not assessed
Identification
Establish documented triage procedures for alerts from SIEM, EDR, NDR, threat intel, user reports, and third party notifications, with consistent severity scoring.
- Triage playbooks
- Severity scoring matrix
- Alert volume and false positive metrics
- Sample case notes
- Different analysts score the same alert differently
- User reports lost in helpdesk queue
- Third party notifications routed to wrong inbox
Define criteria and authority for declaring an incident, initial notification cadence to stakeholders, and engagement of legal, communications, executive sponsors, and external counsel.
- Declaration criteria document
- Notification matrix
- Sample declaration record
- Legal engagement protocol
- Declaration left to analyst discretion
- Executive notified late
- Counsel engaged after public disclosure
Collect and preserve evidence following forensic principles including write protection, hashing, documentation of acquisition, and maintenance of chain of custody for potential legal proceedings.
- Acquisition logs
- Hash verification records
- Chain of custody forms
- Storage location records
- Evidence acquired without write blocker
- Hashes not recorded at acquisition
- Custody forms incomplete
Determine the scope of compromise including affected systems, accounts, data, time window, and threat actor objectives using iterative analysis and pivoting on indicators.
- Scope worksheet
- Pivot pattern analysis
- Affected asset list
- Data exposure assessment
- Scope frozen too early before full picture
- Identity compromise blast radius not assessed
- Data exposure assumed minimal without forensic basis
Lessons Learned
Conduct a post incident review within two weeks of recovery, involving all responders and stakeholders, documenting timeline, what worked, what failed, and actions.
- PIR meeting record
- Timeline reconstruction
- What worked and what failed analysis
- Action register
- PIR held without business stakeholders
- Timeline incomplete due to missing logs
- Actions not assigned with deadlines
Translate lessons into concrete control improvements, new detection rules, updated playbooks, and resource changes, with tracking through to closure and validation in the next exercise.
- Detection backlog
- Playbook update log
- Control improvement projects
- Closure validation in exercises
- Detection rules added but not tested
- Playbook updates not communicated
- Improvement projects starved of budget
Report incident metrics including dwell time, mean time to detect, mean time to contain, mean time to recover, financial impact, and lessons trend analysis to executive risk committees.
- Quarterly IR metrics report
- Executive committee minutes referencing IR
- Trend analysis
- Benchmarking notes
- Metrics tracked but never reported up
- MTTR calculated from declaration only
- Financial impact omitted
Phase 1 - Preparation
Review and codify organizational security policy as foundation for incident handling program
- Incident response plan with named CSIRT roles
- Incident response policy approved by management
- Tabletop exercise records and after-action reports
- Runbooks and jump kit inventory for responders
- CSIRT roles undefined or unstaffed
- Runbooks outdated or never tested
- No tabletop exercises in past 12 months
- Tooling inventory missing or unmaintained
Perform risk assessment to identify sensitive assets and define critical security incidents to focus on
- Incident response plan with named CSIRT roles
- Incident response policy approved by management
- Tabletop exercise records and after-action reports
- Runbooks and jump kit inventory for responders
- CSIRT roles undefined or unstaffed
- Runbooks outdated or never tested
- No tabletop exercises in past 12 months
- Tooling inventory missing or unmaintained
Build Computer Security Incident Response Team with defined roles, responsibilities, and communication strategies
- Incident response plan with named CSIRT roles
- Incident response policy approved by management
- Tabletop exercise records and after-action reports
- Runbooks and jump kit inventory for responders
- CSIRT roles undefined or unstaffed
- Runbooks outdated or never tested
- No tabletop exercises in past 12 months
- Tooling inventory missing or unmaintained
Prepare incident response toolkit, jump bags, documentation templates, and communication procedures
- Incident response plan with named CSIRT roles
- Incident response policy approved by management
- Tabletop exercise records and after-action reports
- Runbooks and jump kit inventory for responders
- CSIRT roles undefined or unstaffed
- Runbooks outdated or never tested
- No tabletop exercises in past 12 months
- Tooling inventory missing or unmaintained
Phase 2 - Identification
Monitor IT systems and detect deviations from normal operations to identify actual security incidents
- SIEM detection rules and alert tuning records
- Incident triage forms and severity classification matrix
- Evidence collection logs with chain of custody
- Detection and analysis runbook
- Alerts not triaged within SLA
- Severity rubric inconsistently applied
- Chain of custody not documented
- Evidence collection skips volatile data
Collect additional evidence when incident discovered, establish type and severity, and document everything
- SIEM detection rules and alert tuning records
- Incident triage forms and severity classification matrix
- Evidence collection logs with chain of custody
- Detection and analysis runbook
- Alerts not triaged within SLA
- Severity rubric inconsistently applied
- Chain of custody not documented
- Evidence collection skips volatile data
Classify and prioritize the incident based on type, severity, and potential business impact
- SIEM detection rules and alert tuning records
- Incident triage forms and severity classification matrix
- Evidence collection logs with chain of custody
- Detection and analysis runbook
- Alerts not triaged within SLA
- Severity rubric inconsistently applied
- Chain of custody not documented
- Evidence collection skips volatile data
Phase 3 - Containment
Perform immediate short-term containment such as isolating affected network segments
- Containment decision log with approver
- Network isolation and host quarantine records
- Forensic image and snapshot records
- Short term and long term containment playbooks
- Short term containment skipped
- No forensic image taken before remediation
- Containment actions not authorised
- Long term containment plan absent
Create forensic images and backups of affected systems before performing further changes
- Containment decision log with approver
- Network isolation and host quarantine records
- Forensic image and snapshot records
- Short term and long term containment playbooks
- Short term containment skipped
- No forensic image taken before remediation
- Containment actions not authorised
- Long term containment plan absent
Apply temporary fixes allowing systems to be used in production while rebuilding clean systems
- Containment decision log with approver
- Network isolation and host quarantine records
- Forensic image and snapshot records
- Short term and long term containment playbooks
- Short term containment skipped
- No forensic image taken before remediation
- Containment actions not authorised
- Long term containment plan absent
Phase 4 - Eradication
Remove the threat from environment including deleting malware and patching exploited vulnerabilities
- Root cause analysis report
- Threat removal verification logs
- Vulnerability remediation tickets linked to incident
- Backdoor and persistence sweep results
- Root cause not identified or only superficial
- Persistence mechanisms missed
- Remediation not validated by independent reviewer
- Recurrence due to incomplete eradication
Identify and address root cause of the incident to prevent recurrence
- Root cause analysis report
- Threat removal verification logs
- Vulnerability remediation tickets linked to incident
- Backdoor and persistence sweep results
- Root cause not identified or only superficial
- Persistence mechanisms missed
- Remediation not validated by independent reviewer
- Recurrence due to incomplete eradication
Thoroughly check for and eliminate multiple backdoors left by sophisticated attackers
- Root cause analysis report
- Threat removal verification logs
- Vulnerability remediation tickets linked to incident
- Backdoor and persistence sweep results
- Root cause not identified or only superficial
- Persistence mechanisms missed
- Remediation not validated by independent reviewer
- Recurrence due to incomplete eradication
Phase 5 - Recovery
Restore systems to normal operation ensuring they are free from security loopholes
- System restoration checklists and sign-off
- Post-restoration vulnerability scan results
- Enhanced monitoring schedule for affected systems
- User and stakeholder communication records
- Restoration completed without verification scans
- Enhanced monitoring window too short
- Backups not validated before restore
- No criteria for declaring incident closed
Rigorously test restored systems to verify security and confirm normal functionality
- System restoration checklists and sign-off
- Post-restoration vulnerability scan results
- Enhanced monitoring schedule for affected systems
- User and stakeholder communication records
- Restoration completed without verification scans
- Enhanced monitoring window too short
- Backups not validated before restore
- No criteria for declaring incident closed
Conduct comprehensive system monitoring after restoration to confirm no re-infection or persistence
- System restoration checklists and sign-off
- Post-restoration vulnerability scan results
- Enhanced monitoring schedule for affected systems
- User and stakeholder communication records
- Restoration completed without verification scans
- Enhanced monitoring window too short
- Backups not validated before restore
- No criteria for declaring incident closed
Phase 6 - Lessons Learned
Analyze incident from start to finish to identify successes and shortcomings in the response
- Post incident review minutes
- Final incident report with metrics
- Plan and control improvement tickets
- Trend analysis across incidents
- Post incident review not held within 14 days
- Improvement actions not tracked to closure
- Metrics not captured (MTTD, MTTR)
- Lessons not fed back into policy or training
Document lessons learned and create comprehensive incident report with timeline and actions taken
- Post incident review minutes
- Final incident report with metrics
- Plan and control improvement tickets
- Trend analysis across incidents
- Post incident review not held within 14 days
- Improvement actions not tracked to closure
- Metrics not captured (MTTD, MTTR)
- Lessons not fed back into policy or training
Use lessons learned to reinforce incident response plan and reduce chances of similar future incidents
- Post incident review minutes
- Final incident report with metrics
- Plan and control improvement tickets
- Trend analysis across incidents
- Post incident review not held within 14 days
- Improvement actions not tracked to closure
- Metrics not captured (MTTD, MTTR)
- Lessons not fed back into policy or training
Preparation
Establish a formal incident response policy and charter approved by executive leadership defining authority, scope, severity tiers, and integration with risk management.
- Signed IR policy
- Charter document
- Executive approval record
- Annual review log
- Policy written but never approved at executive level
- Severity tiers undefined
- No link to risk register
Define IR team structure with named roles, on call rota, and required skills including triage, forensics, malware analysis, and communications, with cross-functional representation.
- Org chart with named roles
- On call rota
- Skills matrix
- Training records and certifications
- Single point of failure on one analyst
- Forensic skills missing
- Communications role unclear during crisis
Maintain a tested jump kit including forensic acquisition tools, write blockers, signed binaries, secure storage media, and out of band communications for use during incidents.
- Jump kit inventory
- Tool validation records
- Out of band comms plan
- Secure storage chain of custody log
- Tools not validated against current OS versions
- Out of band channel unused for years
- Storage media unencrypted
Ensure required log sources are forwarded, retained, and time synchronised, with detection content tuned to known threat patterns and coverage gaps tracked.
- Log source inventory
- Retention policy
- Time sync evidence
- Detection coverage map to threat catalogue
- Endpoint logs not centralised
- Retention shorter than dwell time
- Detection coverage limited to perimeter
Conduct tabletop exercises and technical drills at least annually covering realistic scenarios with internal and external stakeholders, including executive and legal participation.
- Exercise scenarios
- After action reports
- Improvement actions
- Executive participation evidence
- Exercises limited to IT staff
- Lessons not actioned before next exercise
- Same scenario repeated yearly
Recovery
Plan restoration sequence based on business priority, dependencies, and risk of reinfection, with explicit go or no go criteria and back out plan for each system.
- Restoration plan
- Dependency map
- Go or no go decision records
- Back out plan
- Business priority not consulted before sequencing
- Dependencies discovered mid restoration
- No back out plan documented
Validate restored systems are clean using independent scans, baseline comparisons, and enhanced monitoring for a defined hyper care period before declaring recovery complete.
- Validation scan results
- Baseline comparison output
- Hyper care monitoring plan
- Recovery declaration record
- Validation by same tool used for detection
- Hyper care ends too early
- Recovery declared before all hosts validated
Maintain regular communications to internal stakeholders, customers, regulators, and law enforcement as required, with messaging coordinated through legal and communications functions.
- Communications plan
- Stakeholder update cadence records
- Regulatory notifications
- Holding statements
- Customer messaging inconsistent across channels
- Regulatory notifications delayed
- Law enforcement engagement decision not documented
Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does.