Incident Management
Security SpecialistOperations & StrategyDevOpsSRE
No contributors yet. Be the first to contribute!
🔑 Key Takeaway: Decide who leads, how you communicate, and what to freeze before the incident. Web3 response windows are short and many losses are irreversible.
Incident management is preparing for, detecting, responding to, and recovering from security incidents. Plans written under stress lose to plans practiced in calm. This framework covers communication, detection and response, forensic preparation, lessons learned, SEAL-oriented victim playbooks, and a full customizable incident response template with policy, templates, and technical runbooks.
What this framework covers
- Communication Strategies: spokespeople, schedules, and stakeholder updates without spreading unconfirmed claims.
- Incident Detection and Response: find incidents early and work a basic response cycle.
- Forensic Readiness: preserve trustworthy evidence before you need it
(
devpage — in progress). - Lessons Learned: post-incident review that improves the next response.
- Playbooks: scenario playbooks and SEAL 911 victim guidance.
- Incident Response Template: policy, roles, contacts, copy-ready templates, and technical runbooks for Web3 protocols.
Playbooks subsection
- Playbooks overview
- Malware Infection
- North Korea (DPRK) Attack
- Wallet Drainer Attack
- ELUSIVE COMET Attack
- SEAL 911 War Room Guidelines
- Decentralized Incident Response Framework (DeIRF)
Incident response template subsection
- Template overview
- Incident Response Policy
- Roles and Staffing
- Communications
- Contacts
- Templates hub
- Runbooks hub
IR templates
- Incident Log Template
- Post-Mortem Template
- Runbook Template
- Example Incident Log
- Example Post-Mortem
IR runbooks
- Smart Contract Exploit
- Key Compromise
- Frontend Compromise
- DNS Hijack
- CDN/Hosting Compromise
- Dependency Attack
- Build Pipeline Compromise
- DDoS Attack
- Third-Party Outage
Related frameworks
- Monitoring: signals that feed detection
- Multisig for Protocols: emergency signer and admin paths
- Wallet Security: key and signer hygiene adjacent to compromise playbooks
- DPRK IT Workers: long-running human threat context for DPRK playbooks
- Supply Chain: dependency and pipeline incidents
- Infrastructure: DNS, DDoS, and hosting response context
- SEAL Certifications: certification paths related to ops maturity
Further reading
- Incident Response Template: the customization checklist for adapting these documents
- SEAL 911: emergency response coordination
- Rekt News: public post-mortems to learn from