# Dynamic Incident Response > Dynamic Incident Response: A Framework for Security Teams is a free online book by Joshua Wright, a senior instructor at the SANS Institute. The book introduces the Dynamic Approach to Incident Response (DAIR), a framework for managing the full incident response lifecycle. DAIR treats incident response as an adaptive, iterative process rather than a rigid sequential checklist. ## The DAIR Framework DAIR organizes incident response into these activities: - Prepare: Build organizational readiness, train the IR team, develop playbooks - Detect: Establish detection sources, implement threat hunting, deploy Sigma rules - Verify and Triage: Validate incidents, assess risk, determine response priorities - Scope: Determine the full extent of compromise across the environment - Response Actions Loop: Iterate through containment, eradication, and recovery - Contain: Stop attacker activity, preserve evidence, prevent further harm - Eradicate: Remove persistence mechanisms, conduct root cause analysis - Recover: Validate systems, coordinate production restoration, enhance monitoring - Debrief: Document the incident, capture lessons learned, drive improvement ## Topics Covered - Incident response framework and lifecycle (DAIR) - OODA loop applied to incident response decision-making - Ransomware response, negotiation, and recovery - Cloud incident response for AWS, Azure, and GCP - OT/ICS incident response and the Purdue model - Digital forensics: memory analysis, disk forensics, log investigation - Threat intelligence integration (MITRE ATT&CK, Pyramid of Pain, kill chain) - Detection engineering with Sigma rules and SIEM platforms - AI applications in incident response (log analysis, playbook generation, agentic workflows) - NIST CSF 2.0 integration and compliance mapping - Incident response team structure and communication - Post-incident debrief and organizational improvement ## Tools Referenced Sigma, Hayabusa, Volatility, MemProcFS, RITA, Ghidra, PE-bear, pestudio, Nuclei, Nmap, Atomic Red Team, WinPmem, LiME, RECmd, Sysinternals ## Case Studies NotPetya/Maersk, Scattered Spider/MGM, Oldsmar water treatment, RIBridges, CircleCI, Midnight Blizzard/Microsoft, LockBit, Conti/HSE Ireland, Stryker, Salesloft/Drift ## Author Joshua Wright is a senior instructor and author at the SANS Institute, teaching courses on incident response, threat hunting, and penetration testing. He is a senior technical director at Counter Hack. ## Chapters ### Front Matter - Foreword by John Strand: https://dynamicincidentresponse.com/chapters/foreword.html - Preface: https://dynamicincidentresponse.com/chapters/preface.html ### Part 1: Elements of Incident Response - Case Study: Supply Chain Calamity: https://dynamicincidentresponse.com/chapters/supplychaincalamity.html - Introduction: https://dynamicincidentresponse.com/chapters/introduction.html - Getting Started: https://dynamicincidentresponse.com/chapters/gettingstarted.html - Incident Response Models and Their Shortcomings: https://dynamicincidentresponse.com/chapters/existingmodels.html ### Part 2: A Dynamic Approach to Incident Response - A Dynamic Approach to Incident Response: https://dynamicincidentresponse.com/chapters/dynamicapproach.html - Prepare: https://dynamicincidentresponse.com/chapters/prepare.html - Detect: https://dynamicincidentresponse.com/chapters/detect.html - Verify and Triage: https://dynamicincidentresponse.com/chapters/verifytriage.html - Response Actions Loop: https://dynamicincidentresponse.com/chapters/responseactionsloop.html - Scope: https://dynamicincidentresponse.com/chapters/scope.html - Contain: https://dynamicincidentresponse.com/chapters/contain.html - Eradicate: https://dynamicincidentresponse.com/chapters/eradicate.html - Recover: https://dynamicincidentresponse.com/chapters/recover.html - Debrief: https://dynamicincidentresponse.com/chapters/debrief.html ### Part 3: Special Considerations - Accelerating Incident Response with AI: https://dynamicincidentresponse.com/chapters/considerations-ai.html - Incident Response for Ransomware: https://dynamicincidentresponse.com/chapters/considerations-ransomware.html - Incident Response for Cloud Systems: https://dynamicincidentresponse.com/chapters/considerations-cloud.html - Incident Response for Operational Technology: https://dynamicincidentresponse.com/chapters/considerations-ot.html - Integrating DAIR with NIST CSF 2.0: https://dynamicincidentresponse.com/chapters/integration.html - Afterword: https://dynamicincidentresponse.com/chapters/afterward.html ## Links - Website: https://dynamicincidentresponse.com - Chapter listing: https://dynamicincidentresponse.com/chapters.html - Read complete book: https://dynamicir.s3.amazonaws.com/book/dynamicir.html - Download PDF: https://dynamicir.s3.amazonaws.com/dynamicir.pdf - Step-by-step checklists: https://dynamicincidentresponse.com/resources.html - Errata: https://dynamicincidentresponse.com/errata.html