Skip to content

Evidence request lists

SANS Incident Handler's Handbook and PICERL Methodology

Evidence request list. 40 controls, 40 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 12 September 2026. Published by The Art of Service.

Containment

PICERL-C-01
Containment: Short Term Containment Strategy

Apply short term containment such as network segmentation, host isolation, account disablement, or traffic blocking to stop ongoing damage while preserving evidence.

Artefacts an auditor will ask for
  • Containment decision log
  • Isolation evidence such as switchport configs and EDR actions
  • Account disablement records
  • Block list updates
Where this commonly fails
  • Containment delayed by change control
  • Wiping host before evidence collected
  • Account disabled but session tokens remain valid
PICERL-C-02
Containment: System Backup Before Remediation

Capture forensic images and volatile memory of compromised systems before applying remediation steps, with hashed and stored evidence for later analysis.

Artefacts an auditor will ask for
  • Memory and disk image acquisitions
  • Hash logs
  • Storage manifest
  • Imaging tool version log
Where this commonly fails
  • Memory not captured before reboot
  • Imaging skipped under time pressure
  • Storage location not encrypted
PICERL-C-03
Containment: Long Term Containment

Implement long term containment for systems that cannot be immediately rebuilt, including hardening, monitoring uplift, and temporary workarounds maintained until eradication.

Artefacts an auditor will ask for
  • Hardening checklist applied
  • Enhanced monitoring deployment
  • Workaround risk acceptance
  • Exit criteria
Where this commonly fails
  • Workarounds become permanent
  • Monitoring uplift removed too early
  • Risk acceptance not approved at correct level

Eradication

PICERL-E-01
Eradication: Root Cause Analysis

Identify and document root causes including initial access vector, persistence mechanisms, lateral movement paths, and control failures, before applying eradication actions.

Artefacts an auditor will ask for
  • Root cause analysis report
  • Kill chain mapping
  • Control failure analysis
  • Persistence enumeration evidence
Where this commonly fails
  • RCA limited to malware names without control gaps
  • Lateral movement under analysed
  • Persistence not enumerated across all hosts
PICERL-E-02
Eradication: Removal of Threat Actor Artefacts

Remove threat actor artefacts including malware, web shells, accounts, scheduled tasks, services, and persistence mechanisms across all affected systems prior to recovery.

Artefacts an auditor will ask for
  • Eradication checklist by asset
  • Persistence sweep results
  • Account audit
  • Verification scan results
Where this commonly fails
  • Web shells missed in non-standard directories
  • Cloud persistence not enumerated
  • Service accounts created by actor remain
PICERL-E-03
Eradication: Credential Reset and Identity Hygiene

Reset credentials, rotate secrets, invalidate sessions and tokens, and review identity infrastructure for trust abuse such as golden ticket or federation tampering.

Artefacts an auditor will ask for
  • Credential reset records
  • Token invalidation evidence
  • KRBTGT reset log where applicable
  • Federation trust review
Where this commonly fails
  • Service account secrets not rotated
  • Mobile and refresh tokens not invalidated
  • Federation tampering not assessed

Identification

PICERL-I-01
Identification: Detection Sources and Alert Triage

Establish documented triage procedures for alerts from SIEM, EDR, NDR, threat intel, user reports, and third party notifications, with consistent severity scoring.

Artefacts an auditor will ask for
  • Triage playbooks
  • Severity scoring matrix
  • Alert volume and false positive metrics
  • Sample case notes
Where this commonly fails
  • Different analysts score the same alert differently
  • User reports lost in helpdesk queue
  • Third party notifications routed to wrong inbox
PICERL-I-02
Identification: Incident Declaration and Notification

Define criteria and authority for declaring an incident, initial notification cadence to stakeholders, and engagement of legal, communications, executive sponsors, and external counsel.

Artefacts an auditor will ask for
  • Declaration criteria document
  • Notification matrix
  • Sample declaration record
  • Legal engagement protocol
Where this commonly fails
  • Declaration left to analyst discretion
  • Executive notified late
  • Counsel engaged after public disclosure
PICERL-I-03
Identification: Evidence Collection and Chain of Custody

Collect and preserve evidence following forensic principles including write protection, hashing, documentation of acquisition, and maintenance of chain of custody for potential legal proceedings.

Artefacts an auditor will ask for
  • Acquisition logs
  • Hash verification records
  • Chain of custody forms
  • Storage location records
Where this commonly fails
  • Evidence acquired without write blocker
  • Hashes not recorded at acquisition
  • Custody forms incomplete
PICERL-I-04
Identification: Scope Determination

Determine the scope of compromise including affected systems, accounts, data, time window, and threat actor objectives using iterative analysis and pivoting on indicators.

Artefacts an auditor will ask for
  • Scope worksheet
  • Pivot pattern analysis
  • Affected asset list
  • Data exposure assessment
Where this commonly fails
  • Scope frozen too early before full picture
  • Identity compromise blast radius not assessed
  • Data exposure assumed minimal without forensic basis

Lessons Learned

PICERL-L-01
Lessons Learned: Post Incident Review

Conduct a post incident review within two weeks of recovery, involving all responders and stakeholders, documenting timeline, what worked, what failed, and actions.

Artefacts an auditor will ask for
  • PIR meeting record
  • Timeline reconstruction
  • What worked and what failed analysis
  • Action register
Where this commonly fails
  • PIR held without business stakeholders
  • Timeline incomplete due to missing logs
  • Actions not assigned with deadlines
PICERL-L-02
Lessons Learned: Control Improvements and Detection Engineering

Translate lessons into concrete control improvements, new detection rules, updated playbooks, and resource changes, with tracking through to closure and validation in the next exercise.

Artefacts an auditor will ask for
  • Detection backlog
  • Playbook update log
  • Control improvement projects
  • Closure validation in exercises
Where this commonly fails
  • Detection rules added but not tested
  • Playbook updates not communicated
  • Improvement projects starved of budget
PICERL-L-03
Lessons Learned: Metrics and Reporting to Executives

Report incident metrics including dwell time, mean time to detect, mean time to contain, mean time to recover, financial impact, and lessons trend analysis to executive risk committees.

Artefacts an auditor will ask for
  • Quarterly IR metrics report
  • Executive committee minutes referencing IR
  • Trend analysis
  • Benchmarking notes
Where this commonly fails
  • Metrics tracked but never reported up
  • MTTR calculated from declaration only
  • Financial impact omitted

Phase 1 - Preparation

PICERL-P1
Security Policy Review

Review and codify organizational security policy as foundation for incident handling program

Artefacts an auditor will ask for
  • Incident response plan with named CSIRT roles
  • Incident response policy approved by management
  • Tabletop exercise records and after-action reports
  • Runbooks and jump kit inventory for responders
Where this commonly fails
  • CSIRT roles undefined or unstaffed
  • Runbooks outdated or never tested
  • No tabletop exercises in past 12 months
  • Tooling inventory missing or unmaintained
PICERL-P2
Risk Assessment

Perform risk assessment to identify sensitive assets and define critical security incidents to focus on

Artefacts an auditor will ask for
  • Incident response plan with named CSIRT roles
  • Incident response policy approved by management
  • Tabletop exercise records and after-action reports
  • Runbooks and jump kit inventory for responders
Where this commonly fails
  • CSIRT roles undefined or unstaffed
  • Runbooks outdated or never tested
  • No tabletop exercises in past 12 months
  • Tooling inventory missing or unmaintained
PICERL-P3
CSIRT Formation

Build Computer Security Incident Response Team with defined roles, responsibilities, and communication strategies

Artefacts an auditor will ask for
  • Incident response plan with named CSIRT roles
  • Incident response policy approved by management
  • Tabletop exercise records and after-action reports
  • Runbooks and jump kit inventory for responders
Where this commonly fails
  • CSIRT roles undefined or unstaffed
  • Runbooks outdated or never tested
  • No tabletop exercises in past 12 months
  • Tooling inventory missing or unmaintained
PICERL-P4
Tools and Documentation

Prepare incident response toolkit, jump bags, documentation templates, and communication procedures

Artefacts an auditor will ask for
  • Incident response plan with named CSIRT roles
  • Incident response policy approved by management
  • Tabletop exercise records and after-action reports
  • Runbooks and jump kit inventory for responders
Where this commonly fails
  • CSIRT roles undefined or unstaffed
  • Runbooks outdated or never tested
  • No tabletop exercises in past 12 months
  • Tooling inventory missing or unmaintained

Phase 2 - Identification

PICERL-I1
Monitoring and Detection

Monitor IT systems and detect deviations from normal operations to identify actual security incidents

Artefacts an auditor will ask for
  • SIEM detection rules and alert tuning records
  • Incident triage forms and severity classification matrix
  • Evidence collection logs with chain of custody
  • Detection and analysis runbook
Where this commonly fails
  • Alerts not triaged within SLA
  • Severity rubric inconsistently applied
  • Chain of custody not documented
  • Evidence collection skips volatile data
PICERL-I2
Evidence Collection

Collect additional evidence when incident discovered, establish type and severity, and document everything

Artefacts an auditor will ask for
  • SIEM detection rules and alert tuning records
  • Incident triage forms and severity classification matrix
  • Evidence collection logs with chain of custody
  • Detection and analysis runbook
Where this commonly fails
  • Alerts not triaged within SLA
  • Severity rubric inconsistently applied
  • Chain of custody not documented
  • Evidence collection skips volatile data
PICERL-I3
Incident Classification

Classify and prioritize the incident based on type, severity, and potential business impact

Artefacts an auditor will ask for
  • SIEM detection rules and alert tuning records
  • Incident triage forms and severity classification matrix
  • Evidence collection logs with chain of custody
  • Detection and analysis runbook
Where this commonly fails
  • Alerts not triaged within SLA
  • Severity rubric inconsistently applied
  • Chain of custody not documented
  • Evidence collection skips volatile data

Phase 3 - Containment

PICERL-C1
Short-Term Containment

Perform immediate short-term containment such as isolating affected network segments

Artefacts an auditor will ask for
  • Containment decision log with approver
  • Network isolation and host quarantine records
  • Forensic image and snapshot records
  • Short term and long term containment playbooks
Where this commonly fails
  • Short term containment skipped
  • No forensic image taken before remediation
  • Containment actions not authorised
  • Long term containment plan absent
PICERL-C2
System Backup

Create forensic images and backups of affected systems before performing further changes

Artefacts an auditor will ask for
  • Containment decision log with approver
  • Network isolation and host quarantine records
  • Forensic image and snapshot records
  • Short term and long term containment playbooks
Where this commonly fails
  • Short term containment skipped
  • No forensic image taken before remediation
  • Containment actions not authorised
  • Long term containment plan absent
PICERL-C3
Long-Term Containment

Apply temporary fixes allowing systems to be used in production while rebuilding clean systems

Artefacts an auditor will ask for
  • Containment decision log with approver
  • Network isolation and host quarantine records
  • Forensic image and snapshot records
  • Short term and long term containment playbooks
Where this commonly fails
  • Short term containment skipped
  • No forensic image taken before remediation
  • Containment actions not authorised
  • Long term containment plan absent

Phase 4 - Eradication

PICERL-E1
Threat Removal

Remove the threat from environment including deleting malware and patching exploited vulnerabilities

Artefacts an auditor will ask for
  • Root cause analysis report
  • Threat removal verification logs
  • Vulnerability remediation tickets linked to incident
  • Backdoor and persistence sweep results
Where this commonly fails
  • Root cause not identified or only superficial
  • Persistence mechanisms missed
  • Remediation not validated by independent reviewer
  • Recurrence due to incomplete eradication
PICERL-E2
Root Cause Analysis

Identify and address root cause of the incident to prevent recurrence

Artefacts an auditor will ask for
  • Root cause analysis report
  • Threat removal verification logs
  • Vulnerability remediation tickets linked to incident
  • Backdoor and persistence sweep results
Where this commonly fails
  • Root cause not identified or only superficial
  • Persistence mechanisms missed
  • Remediation not validated by independent reviewer
  • Recurrence due to incomplete eradication
PICERL-E3
Backdoor Elimination

Thoroughly check for and eliminate multiple backdoors left by sophisticated attackers

Artefacts an auditor will ask for
  • Root cause analysis report
  • Threat removal verification logs
  • Vulnerability remediation tickets linked to incident
  • Backdoor and persistence sweep results
Where this commonly fails
  • Root cause not identified or only superficial
  • Persistence mechanisms missed
  • Remediation not validated by independent reviewer
  • Recurrence due to incomplete eradication

Phase 5 - Recovery

PICERL-R1
System Restoration

Restore systems to normal operation ensuring they are free from security loopholes

Artefacts an auditor will ask for
  • System restoration checklists and sign-off
  • Post-restoration vulnerability scan results
  • Enhanced monitoring schedule for affected systems
  • User and stakeholder communication records
Where this commonly fails
  • Restoration completed without verification scans
  • Enhanced monitoring window too short
  • Backups not validated before restore
  • No criteria for declaring incident closed
PICERL-R2
Security Verification

Rigorously test restored systems to verify security and confirm normal functionality

Artefacts an auditor will ask for
  • System restoration checklists and sign-off
  • Post-restoration vulnerability scan results
  • Enhanced monitoring schedule for affected systems
  • User and stakeholder communication records
Where this commonly fails
  • Restoration completed without verification scans
  • Enhanced monitoring window too short
  • Backups not validated before restore
  • No criteria for declaring incident closed
PICERL-R3
Enhanced Monitoring

Conduct comprehensive system monitoring after restoration to confirm no re-infection or persistence

Artefacts an auditor will ask for
  • System restoration checklists and sign-off
  • Post-restoration vulnerability scan results
  • Enhanced monitoring schedule for affected systems
  • User and stakeholder communication records
Where this commonly fails
  • Restoration completed without verification scans
  • Enhanced monitoring window too short
  • Backups not validated before restore
  • No criteria for declaring incident closed

Phase 6 - Lessons Learned

PICERL-L1
Post-Incident Review

Analyze incident from start to finish to identify successes and shortcomings in the response

Artefacts an auditor will ask for
  • Post incident review minutes
  • Final incident report with metrics
  • Plan and control improvement tickets
  • Trend analysis across incidents
Where this commonly fails
  • Post incident review not held within 14 days
  • Improvement actions not tracked to closure
  • Metrics not captured (MTTD, MTTR)
  • Lessons not fed back into policy or training
PICERL-L2
Documentation and Reporting

Document lessons learned and create comprehensive incident report with timeline and actions taken

Artefacts an auditor will ask for
  • Post incident review minutes
  • Final incident report with metrics
  • Plan and control improvement tickets
  • Trend analysis across incidents
Where this commonly fails
  • Post incident review not held within 14 days
  • Improvement actions not tracked to closure
  • Metrics not captured (MTTD, MTTR)
  • Lessons not fed back into policy or training
PICERL-L3
Plan Improvement

Use lessons learned to reinforce incident response plan and reduce chances of similar future incidents

Artefacts an auditor will ask for
  • Post incident review minutes
  • Final incident report with metrics
  • Plan and control improvement tickets
  • Trend analysis across incidents
Where this commonly fails
  • Post incident review not held within 14 days
  • Improvement actions not tracked to closure
  • Metrics not captured (MTTD, MTTR)
  • Lessons not fed back into policy or training

Preparation

PICERL-P-01
Preparation: Incident Response Policy and Charter

Establish a formal incident response policy and charter approved by executive leadership defining authority, scope, severity tiers, and integration with risk management.

Artefacts an auditor will ask for
  • Signed IR policy
  • Charter document
  • Executive approval record
  • Annual review log
Where this commonly fails
  • Policy written but never approved at executive level
  • Severity tiers undefined
  • No link to risk register
PICERL-P-02
Preparation: Incident Response Team Roles and Skills

Define IR team structure with named roles, on call rota, and required skills including triage, forensics, malware analysis, and communications, with cross-functional representation.

Artefacts an auditor will ask for
  • Org chart with named roles
  • On call rota
  • Skills matrix
  • Training records and certifications
Where this commonly fails
  • Single point of failure on one analyst
  • Forensic skills missing
  • Communications role unclear during crisis
PICERL-P-03
Preparation: Jump Kit and Tooling Readiness

Maintain a tested jump kit including forensic acquisition tools, write blockers, signed binaries, secure storage media, and out of band communications for use during incidents.

Artefacts an auditor will ask for
  • Jump kit inventory
  • Tool validation records
  • Out of band comms plan
  • Secure storage chain of custody log
Where this commonly fails
  • Tools not validated against current OS versions
  • Out of band channel unused for years
  • Storage media unencrypted
PICERL-P-04
Preparation: Logging, Detection, and Telemetry Baseline

Ensure required log sources are forwarded, retained, and time synchronised, with detection content tuned to known threat patterns and coverage gaps tracked.

Artefacts an auditor will ask for
  • Log source inventory
  • Retention policy
  • Time sync evidence
  • Detection coverage map to threat catalogue
Where this commonly fails
  • Endpoint logs not centralised
  • Retention shorter than dwell time
  • Detection coverage limited to perimeter
PICERL-P-05
Preparation: Tabletop Exercises and Drills

Conduct tabletop exercises and technical drills at least annually covering realistic scenarios with internal and external stakeholders, including executive and legal participation.

Artefacts an auditor will ask for
  • Exercise scenarios
  • After action reports
  • Improvement actions
  • Executive participation evidence
Where this commonly fails
  • Exercises limited to IT staff
  • Lessons not actioned before next exercise
  • Same scenario repeated yearly

Recovery

PICERL-R-01
Recovery: Restoration Planning and Sequencing

Plan restoration sequence based on business priority, dependencies, and risk of reinfection, with explicit go or no go criteria and back out plan for each system.

Artefacts an auditor will ask for
  • Restoration plan
  • Dependency map
  • Go or no go decision records
  • Back out plan
Where this commonly fails
  • Business priority not consulted before sequencing
  • Dependencies discovered mid restoration
  • No back out plan documented
PICERL-R-02
Recovery: Validation and Monitoring

Validate restored systems are clean using independent scans, baseline comparisons, and enhanced monitoring for a defined hyper care period before declaring recovery complete.

Artefacts an auditor will ask for
  • Validation scan results
  • Baseline comparison output
  • Hyper care monitoring plan
  • Recovery declaration record
Where this commonly fails
  • Validation by same tool used for detection
  • Hyper care ends too early
  • Recovery declared before all hosts validated
PICERL-R-03
Recovery: Communications and Stakeholder Updates

Maintain regular communications to internal stakeholders, customers, regulators, and law enforcement as required, with messaging coordinated through legal and communications functions.

Artefacts an auditor will ask for
  • Communications plan
  • Stakeholder update cadence records
  • Regulatory notifications
  • Holding statements
Where this commonly fails
  • Customer messaging inconsistent across channels
  • Regulatory notifications delayed
  • Law enforcement engagement decision not documented
Assembled from the framework's own control set. Every line traces to a control in the graph, so this pack is regenerated rather than written, and stays current as the graph does.

Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does.