Free for the community

Dynamic
Incident
Response

A Framework for Security Teams

A practical framework for security teams handling real-world incidents where new findings, shifting priorities, and active attackers make response anything but linear.

  • Contributed chapters on ransomware, cloud, and operational technology
  • AI-accelerated response, including MCP and agentic workflows
  • Direct crosswalk to NIST CSF 2.0
Dynamic Incident Response: A Framework for Security Teams, book cover

Free to read, share, and adapt · CC BY 4.0. No purchase, no login.

Get the book

Every format. Every one of them free.

Read it in your browser, keep a copy on your e-reader, or order the paperback at cost. Pick the format that fits how you work.

Read Online

HTML

The complete book as a single page in your browser, with full-resolution figures and a floating table of contents you can search.

Open the Book

Read by Chapter

HTML

Twenty-three fast-loading chapter pages you can bookmark, link to, and share. Jump straight to the topic you need.

Browse Chapters

Download PDF

8.5 × 11

Letter-size PDF for offline reading, printing, or loading into your own tools and AI agents.

Download PDF

Download EPUB

E-reader

Reflowable EPUB for Apple Books, Kobo, or whatever reader app you use.

Download EPUB

Kindle Edition

Amazon

Free on the Kindle store. Send it to your Kindle device or read it in the Kindle app.

Coming Soon

Paperback

Print

Prefer paper? The 720-page print edition ships from Amazon print-on-demand at production cost. No markup.

Coming Soon
Step-by-Step companion guides

Checklists for the moment you need them.

Each DAIR waypoint has a companion guide that condenses the chapter into a checklist you can work from. Print the PDF for your war room, or drop the Markdown into your ticketing system, wiki, or AI agent.

PrepareReadiness, teams, plans, toolingPDFMD
DetectSources, hunting, Sigma, SIEMPDFMD
Verify and TriageConfirm, assess, prioritizePDFMD
Response Actions LoopRunning the iterative cyclePDFMD
ScopeIOC hunting, lateral movementPDFMD
ContainIsolation, credentials, evidencePDFMD
EradicatePersistence, root cause, remediationPDFMD
RecoverValidation, restoration, monitoringPDFMD
DebriefLessons learned, improvementPDFMD

See all companion guides with descriptions →

What readers are saying
Joshua Wright has long been one of the most respected minds in cybersecurity, and this book shows exactly why. Dynamic IR challenges the traditional checkbox approach to incident response and replaces it with a practical, adaptive model built for the realities defenders face today.
David KennedyFounder and CEO, TrustedSec and Binary Defense
There is no better authority to help bring about an updated, and much needed, incident response process to the community than Joshua Wright.
Rob M. LeeCEO and Founder, Dragos
Most incident response books teach you to follow the steps. Josh Wright's Dynamic Incident Response teaches you what to do when the steps stop working. He doesn't offer a new checklist. He offers a way of thinking that survives contact with real incidents.
Rob T. LeeChief AI Officer and Chief of Research, SANS Institute
I've seen too many breach reports where defenders detected attackers early but scoped poorly, eradicated incompletely, or prioritized prevention without detection. Dynamic Incident Response is a clear, practical guide to real-world, iterative incident response, and I'll be recommending it widely.
Jeff McJunkinPenetration Tester and SANS Author
Josh dives straight into the details, making it a gripping read that's hard to put down. It challenges old-school thinking about incidents, explains why attackers often have the advantage, and shows how we can actually improve.
Chris DaleChief Hacking Officer, River Security
Joshua Wright gave the community a generous gift with Dynamic Incident Response. It's the definitive, practical guide we needed for today's cloud-native, AI-enabled environments. Read it, refer to it, feed it to your AI agents, and your incident response work will be a lot less stressful and far more effective.
Lenny ZeltserSANS Institute Faculty Fellow
Joshua provides a grounded, actionable, and vital evolution in Incident Response methodology. Rooted in operational reality, this new model reflects the need for organizational context and iterative investigations.
Alan WatsonNASA Cybersecurity Incident Response Team
In a world that relies more and more on tools, abstractions, and vendors, books like this are essential. Work like this pushes the craft back toward first principles, where understanding the system matters more than hoping a vendor's tooling was working correctly.
Kevin TyersSenior Manager, GitHub
Why this book matters

Incident response has never been as linear as the models pretend it is.

Traditional frameworks like PICERL and NIST SP 800-61 treat response as a clean sequence: prepare, identify, contain, eradicate, recover. In practice, that sequence breaks down constantly. Attackers return after containment. Scope gets underestimated. Eradication efforts miss the persistence mechanisms that quietly restore access. The models aren't wrong, but they were built for a simpler era.

Dynamic Incident Response introduces DAIR, the Dynamic Approach to Incident Response: a model built around explicit Verify and Triage and Scoping waypoints and a Response Actions Loop of Scope, Contain, Eradicate, and Recover that responders re-enter as new evidence surfaces.

Traditional approach

Linear, and confident until it isn't

Useful for teaching the basics, but the sequence assumes attackers stay contained once you act, and that scope is knowable up front. Neither is reliably true.

DAIR approach

Built around verification, triage, and scope

DAIR treats those steps as explicit parts of the model, not afterthoughts, so response can adjust as the picture of the incident changes.

From the foreword
Right then and there, I knew something important. No matter how hard I worked to become the best instructor that SANS ever produced, that title was already taken. Josh had it.
John Strand, Owner, Black Hills Information Security

John Strand has known Josh Wright since Josh took over SANS SEC504 from him, just as John had taken it over from Ed Skoudis. His foreword traces that lineage and introduces the book.

Read the Full Foreword

What's inside

A framework, and the specific situations it has to hold up in.

Twenty chapters across three parts: the elements of incident response, the DAIR model itself, and how it plays out in the domains giving security teams the most trouble right now.

01

The DAIR Model

The waypoints, outcomes, and Response Actions Loop that replace a fixed sequence with a cycle responders can re-enter as new evidence appears. Built on the OODA loop and aligned with NIST CSF 2.0.

02

Detection and Threat Hunting

Identify threats early with signature-based, behavioral, and AI-driven detection. Sigma rules, SIEM correlation, endpoint detection and response, and network traffic analysis.

03

Verify, Triage, and Scope

The explicit steps most frameworks skip: confirming an event is real before committing resources, and understanding the true extent of a compromise before declaring it contained.

04

Ransomware Response

Applying DAIR to ransomware and multi-vector extortion: exfiltration detection, decryption assessment, the 3-2-1-1-0 backup rule, and lessons from NotPetya, LockBit, and Scattered Spider.

05

Cloud Incident Response

Identity-first containment, ephemeral resource investigation, and cloud-native recovery across AWS, Azure, and GCP. CloudTrail and Azure Monitor analysis, IAM persistence hunting, and Kubernetes response.

06

Operational Technology

Response for OT and ICS environments where safety and physical processes introduce constraints that don't exist in a typical IT incident. Purdue model evidence mapping and controlled island-mode operations.

07

Digital Forensics and Investigation

Memory forensics with Volatility and MemProcFS, Windows event log analysis with Hayabusa, disk forensics, malware analysis, lateral movement detection, and root cause analysis.

08

AI-Accelerated Response

Practical uses of generative AI in log analysis, playbook generation, and report writing, plus MCP-based agentic workflows, with direct guidance on where to trust the output and where not to.

09

NIST CSF 2.0 Crosswalk

Map DAIR activities to all six CSF 2.0 functions: Govern, Identify, Protect, Detect, Respond, and Recover. Build compliance artifacts from your incident response operations.

Author and contributors

Domain expertise in the areas giving responders the most trouble.

Joshua Wright is a SANS Faculty Fellow and the author of SANS SEC504: Hacker Tools, Techniques, and Incident Handling. Contributing authors expand the DAIR model into ransomware, cloud, and operational technology.

Joshua Wright

Joshua Wright

Author · SANS Faculty Fellow, SEC504 author and instructor

Ryan Chapman

Ryan Chapman

Contributor · Ransomware and cyber extortion response

Megan Roddie-Fonseca

Megan Roddie-Fonseca

Contributor · Cloud incident response

Dean Parsons

Dean Parsons

Contributor · Operational technology and control systems

Frequently asked questions
What is the Dynamic Approach to Incident Response (DAIR)?
DAIR is an iterative incident response framework introduced in this book. It organizes response around five waypoints (Prepare, Detect, Verify and Triage, Response Actions, and Debrief) and a Response Actions Loop of Scope, Contain, Eradicate, and Recover that responders re-enter as new evidence appears. DAIR is built on Boyd's OODA loop and includes a crosswalk to NIST CSF 2.0.
Is this book free to read?
Yes. The complete book is free in every format: read it online, browse by chapter, or download the PDF or EPUB. The Kindle edition is free on Amazon, and the paperback is sold at production cost. No purchase or registration is required. The book is licensed under Creative Commons Attribution 4.0 (CC BY 4.0).
What formats is the book available in?
Single-page HTML, individual HTML chapters, 8.5 by 11 inch PDF, EPUB for e-readers, Kindle, and paperback. See Get the Book for links to each.
What topics does the book cover?
The full incident response lifecycle: preparation, detection and threat hunting, verification and triage, scoping, containment, eradication, recovery, and debrief. Dedicated chapters cover ransomware and cyber extortion response, cloud incident response for AWS, Azure, and GCP, OT/ICS security, digital forensics and memory analysis, cyber threat intelligence, incident response playbook development, AI-accelerated response including MCP and agentic workflows, and NIST CSF 2.0 compliance mapping.
What are the Step-by-Step companion guides?
Each DAIR waypoint has a companion guide that condenses the chapter into an actionable checklist for use during an active incident. The nine guides cover Prepare, Detect, Verify and Triage, the Response Actions Loop, Scope, Contain, Eradicate, Recover, and Debrief. All are free downloads in PDF and Markdown formats from the Step-by-Step Guides page.
How does DAIR differ from traditional incident response models?
Traditional models like PICERL and NIST SP 800-61 present incident response as a linear sequence of phases. DAIR adds explicit Verify and Triage and Scoping waypoints, and a Response Actions Loop where scoping, containment, eradication, and recovery repeat as new evidence emerges. It treats incident response as an iterative process that adapts to the incident rather than a checklist to follow in order.
Who wrote this book?
Joshua Wright is a SANS Faculty Fellow and the author of SANS SEC504. The book includes contributed chapters from Ryan Chapman on ransomware, Megan Roddie-Fonseca on cloud incident response, and Dean Parsons on operational technology, and a foreword by John Strand.
Ready when you are

Modern incident response is iterative.
Your framework should be too.

Free for you to read, share, and adapt under CC BY 4.0. No purchase, no login.