RESOURCE / EN

Incident response checklist

Short list: intake, facts, decision, note. Not a 24/7 playbook.

Intake

  • what was reported (symptom, not diagnosis)
  • which host / account / time (timezone)
  • who can decide on isolation
  • whether anyone already rebooted / cleared logs

Facts (not hypotheses)

  • 4624/4625 or Linux auth — if that is the event type
  • process / service if visible in the log
  • network: source, port, direction — if visible
  • gaps (what is missing)

Decision

  • watch / isolate / escalate — with a reason
  • alert ≠ incident until you write why

Note

  • timeline
  • actions and who did them
  • next step and deadline

Isolation without an owner is theatre. This list does not replace law, HR or insurance.