Skip to content
Logo

Incident Management

Security SpecialistOperations & StrategyDevOpsSRE

No contributors yet. Be the first to contribute!

🔑 Key Takeaway: Decide who leads, how you communicate, and what to freeze before the incident. Web3 response windows are short and many losses are irreversible.

Incident management is preparing for, detecting, responding to, and recovering from security incidents. Plans written under stress lose to plans practiced in calm. This framework covers communication, detection and response, forensic preparation, lessons learned, SEAL-oriented victim playbooks, and a full customizable incident response template with policy, templates, and technical runbooks.

What this framework covers

  1. Communication Strategies: spokespeople, schedules, and stakeholder updates without spreading unconfirmed claims.
  2. Incident Detection and Response: find incidents early and work a basic response cycle.
  3. Forensic Readiness: preserve trustworthy evidence before you need it (dev page — in progress).
  4. Lessons Learned: post-incident review that improves the next response.
  5. Playbooks: scenario playbooks and SEAL 911 victim guidance.
  6. Incident Response Template: policy, roles, contacts, copy-ready templates, and technical runbooks for Web3 protocols.

Playbooks subsection

  1. Playbooks overview
  2. Malware Infection
  3. North Korea (DPRK) Attack
  4. Wallet Drainer Attack
  5. ELUSIVE COMET Attack
  6. SEAL 911 War Room Guidelines
  7. Decentralized Incident Response Framework (DeIRF)

Incident response template subsection

  1. Template overview
  2. Incident Response Policy
  3. Roles and Staffing
  4. Communications
  5. Contacts
  6. Templates hub
  7. Runbooks hub

IR templates

  1. Incident Log Template
  2. Post-Mortem Template
  3. Runbook Template
  4. Example Incident Log
  5. Example Post-Mortem

IR runbooks

  1. Smart Contract Exploit
  2. Key Compromise
  3. Frontend Compromise
  4. DNS Hijack
  5. CDN/Hosting Compromise
  6. Dependency Attack
  7. Build Pipeline Compromise
  8. DDoS Attack
  9. Third-Party Outage

Further reading