Runbook
A runbook is a detailed operational procedure outlining the technical steps for a specific task.
A runbook is a technical, step-by-step guide for a specific task. It describes the exact commands or clicks needed within a particular system.
How it works
Runbooks are the tools that a playbook calls upon. For example, a playbook might state: 'Lock a compromised account.' The runbook then describes how to do this in Entra ID, the VPN, and the on-premises Active Directory. Good runbooks are precise enough for someone without prior system knowledge to follow them correctly at night.
For instance, a runbook for isolating an endpoint details the EDR command and the necessary permissions. It also specifies how to verify that the isolation is active. The runbook also documents how to reverse the isolation process. Many of these runbooks can be implemented directly as automated actions.
What to look out for
- Accuracy: Runbooks must be checked after every system change.
- Permissions: Document which account is authorised to perform the steps.
- Rollback plan: Every intervention needs instructions for reversing it.
- Storage: Runbooks must be accessible even when central systems are offline.
How it relates to automation
A well-written runbook provides the best template for automation. Conversely, the runbook serves as a fallback if the automation fails. Both should therefore be maintained together.
Typical mistakes
Runbooks are often stored in a wiki that is affected during an attack. Therefore, keep a copy outside of the production environment. A second mistake is having instructions that require permissions nobody has at night. Always test runbooks using the exact accounts that would be used in an emergency. Outdated screenshots and menu paths are another common problem following updates.
How we implement it
Approved response actions are carried out according to defined procedures and within your mandate.