When the critical alarm arrives, first hour decisions determine the damage. This playbook is for SIEM-focused SOC teams.
- Verify alarm — false positive? Open the relevant log lines.
- open Incident — single ticket, connect all associated alarms.
- List affected assets — IP, user, host.
- containment — firewall deny, account disabled (approved).
- Lock logs — Don't delete retention, get forensic bundle.
- timeline — Populate the SIEM timeline view.
- Contact — management and legal information.
- Root cause hypothesis — do not share until it is proven yet.
- Tag MITER — T1110, T1190 etc. for reporting.
- Improvement — update rule, close detection gap.
OxiSec incident builder automatically groups associated alarms; A.I. provides summary “what happened / what to do”.