Dynamic
Incident
Response
A Framework for Security Teams
A practical framework for security teams handling real-world incidents where new findings, shifting priorities, and active attackers make response anything but linear.
Free to read, share, and adapt · CC BY 4.0. No purchase, no login.
Every format. Every one of them free.
Read it in your browser, keep a copy on your e-reader, or order the paperback at cost. Pick the format that fits how you work.
Read Online
HTMLThe complete book as a single page in your browser, with full-resolution figures and a floating table of contents you can search.
Open the BookRead by Chapter
HTMLTwenty-three fast-loading chapter pages you can bookmark, link to, and share. Jump straight to the topic you need.
Browse ChaptersDownload PDF
8.5 × 11Letter-size PDF for offline reading, printing, or loading into your own tools and AI agents.
Download PDFDownload EPUB
E-readerReflowable EPUB for Apple Books, Kobo, or whatever reader app you use.
Download EPUBKindle Edition
AmazonFree on the Kindle store. Send it to your Kindle device or read it in the Kindle app.
Coming SoonPaperback
PrintPrefer paper? The 720-page print edition ships from Amazon print-on-demand at production cost. No markup.
Coming SoonChecklists for the moment you need them.
Each DAIR waypoint has a companion guide that condenses the chapter into a checklist you can work from. Print the PDF for your war room, or drop the Markdown into your ticketing system, wiki, or AI agent.
Joshua Wright has long been one of the most respected minds in cybersecurity, and this book shows exactly why. Dynamic IR challenges the traditional checkbox approach to incident response and replaces it with a practical, adaptive model built for the realities defenders face today.David KennedyFounder and CEO, TrustedSec and Binary Defense
There is no better authority to help bring about an updated, and much needed, incident response process to the community than Joshua Wright.Rob M. LeeCEO and Founder, Dragos
Most incident response books teach you to follow the steps. Josh Wright's Dynamic Incident Response teaches you what to do when the steps stop working. He doesn't offer a new checklist. He offers a way of thinking that survives contact with real incidents.Rob T. LeeChief AI Officer and Chief of Research, SANS Institute
I've seen too many breach reports where defenders detected attackers early but scoped poorly, eradicated incompletely, or prioritized prevention without detection. Dynamic Incident Response is a clear, practical guide to real-world, iterative incident response, and I'll be recommending it widely.Jeff McJunkinPenetration Tester and SANS Author
Josh dives straight into the details, making it a gripping read that's hard to put down. It challenges old-school thinking about incidents, explains why attackers often have the advantage, and shows how we can actually improve.Chris DaleChief Hacking Officer, River Security
Joshua Wright gave the community a generous gift with Dynamic Incident Response. It's the definitive, practical guide we needed for today's cloud-native, AI-enabled environments. Read it, refer to it, feed it to your AI agents, and your incident response work will be a lot less stressful and far more effective.Lenny ZeltserSANS Institute Faculty Fellow
Joshua provides a grounded, actionable, and vital evolution in Incident Response methodology. Rooted in operational reality, this new model reflects the need for organizational context and iterative investigations.Alan WatsonNASA Cybersecurity Incident Response Team
In a world that relies more and more on tools, abstractions, and vendors, books like this are essential. Work like this pushes the craft back toward first principles, where understanding the system matters more than hoping a vendor's tooling was working correctly.Kevin TyersSenior Manager, GitHub
Incident response has never been as linear as the models pretend it is.
Traditional frameworks like PICERL and NIST SP 800-61 treat response as a clean sequence: prepare, identify, contain, eradicate, recover. In practice, that sequence breaks down constantly. Attackers return after containment. Scope gets underestimated. Eradication efforts miss the persistence mechanisms that quietly restore access. The models aren't wrong, but they were built for a simpler era.
Dynamic Incident Response introduces DAIR, the Dynamic Approach to Incident Response: a model built around explicit Verify and Triage and Scoping waypoints and a Response Actions Loop of Scope, Contain, Eradicate, and Recover that responders re-enter as new evidence surfaces.
Linear, and confident until it isn't
Useful for teaching the basics, but the sequence assumes attackers stay contained once you act, and that scope is knowable up front. Neither is reliably true.
Built around verification, triage, and scope
DAIR treats those steps as explicit parts of the model, not afterthoughts, so response can adjust as the picture of the incident changes.
Right then and there, I knew something important. No matter how hard I worked to become the best instructor that SANS ever produced, that title was already taken. Josh had it.
John Strand has known Josh Wright since Josh took over SANS SEC504 from him, just as John had taken it over from Ed Skoudis. His foreword traces that lineage and introduces the book.
A framework, and the specific situations it has to hold up in.
Twenty chapters across three parts: the elements of incident response, the DAIR model itself, and how it plays out in the domains giving security teams the most trouble right now.
The DAIR Model
The waypoints, outcomes, and Response Actions Loop that replace a fixed sequence with a cycle responders can re-enter as new evidence appears. Built on the OODA loop and aligned with NIST CSF 2.0.
Detection and Threat Hunting
Identify threats early with signature-based, behavioral, and AI-driven detection. Sigma rules, SIEM correlation, endpoint detection and response, and network traffic analysis.
Verify, Triage, and Scope
The explicit steps most frameworks skip: confirming an event is real before committing resources, and understanding the true extent of a compromise before declaring it contained.
Ransomware Response
Applying DAIR to ransomware and multi-vector extortion: exfiltration detection, decryption assessment, the 3-2-1-1-0 backup rule, and lessons from NotPetya, LockBit, and Scattered Spider.
Cloud Incident Response
Identity-first containment, ephemeral resource investigation, and cloud-native recovery across AWS, Azure, and GCP. CloudTrail and Azure Monitor analysis, IAM persistence hunting, and Kubernetes response.
Operational Technology
Response for OT and ICS environments where safety and physical processes introduce constraints that don't exist in a typical IT incident. Purdue model evidence mapping and controlled island-mode operations.
Digital Forensics and Investigation
Memory forensics with Volatility and MemProcFS, Windows event log analysis with Hayabusa, disk forensics, malware analysis, lateral movement detection, and root cause analysis.
AI-Accelerated Response
Practical uses of generative AI in log analysis, playbook generation, and report writing, plus MCP-based agentic workflows, with direct guidance on where to trust the output and where not to.
NIST CSF 2.0 Crosswalk
Map DAIR activities to all six CSF 2.0 functions: Govern, Identify, Protect, Detect, Respond, and Recover. Build compliance artifacts from your incident response operations.
Domain expertise in the areas giving responders the most trouble.
Joshua Wright is a SANS Faculty Fellow and the author of SANS SEC504: Hacker Tools, Techniques, and Incident Handling. Contributing authors expand the DAIR model into ransomware, cloud, and operational technology.
Joshua Wright
Author · SANS Faculty Fellow, SEC504 author and instructor
Ryan Chapman
Contributor · Ransomware and cyber extortion response
Megan Roddie-Fonseca
Contributor · Cloud incident response
Dean Parsons
Contributor · Operational technology and control systems
- What is the Dynamic Approach to Incident Response (DAIR)?
- DAIR is an iterative incident response framework introduced in this book. It organizes response around five waypoints (Prepare, Detect, Verify and Triage, Response Actions, and Debrief) and a Response Actions Loop of Scope, Contain, Eradicate, and Recover that responders re-enter as new evidence appears. DAIR is built on Boyd's OODA loop and includes a crosswalk to NIST CSF 2.0.
- Is this book free to read?
- Yes. The complete book is free in every format: read it online, browse by chapter, or download the PDF or EPUB. The Kindle edition is free on Amazon, and the paperback is sold at production cost. No purchase or registration is required. The book is licensed under Creative Commons Attribution 4.0 (CC BY 4.0).
- What formats is the book available in?
- Single-page HTML, individual HTML chapters, 8.5 by 11 inch PDF, EPUB for e-readers, Kindle, and paperback. See Get the Book for links to each.
- What topics does the book cover?
- The full incident response lifecycle: preparation, detection and threat hunting, verification and triage, scoping, containment, eradication, recovery, and debrief. Dedicated chapters cover ransomware and cyber extortion response, cloud incident response for AWS, Azure, and GCP, OT/ICS security, digital forensics and memory analysis, cyber threat intelligence, incident response playbook development, AI-accelerated response including MCP and agentic workflows, and NIST CSF 2.0 compliance mapping.
- What are the Step-by-Step companion guides?
- Each DAIR waypoint has a companion guide that condenses the chapter into an actionable checklist for use during an active incident. The nine guides cover Prepare, Detect, Verify and Triage, the Response Actions Loop, Scope, Contain, Eradicate, Recover, and Debrief. All are free downloads in PDF and Markdown formats from the Step-by-Step Guides page.
- How does DAIR differ from traditional incident response models?
- Traditional models like PICERL and NIST SP 800-61 present incident response as a linear sequence of phases. DAIR adds explicit Verify and Triage and Scoping waypoints, and a Response Actions Loop where scoping, containment, eradication, and recovery repeat as new evidence emerges. It treats incident response as an iterative process that adapts to the incident rather than a checklist to follow in order.
- Who wrote this book?
- Joshua Wright is a SANS Faculty Fellow and the author of SANS SEC504. The book includes contributed chapters from Ryan Chapman on ransomware, Megan Roddie-Fonseca on cloud incident response, and Dean Parsons on operational technology, and a foreword by John Strand.
Modern incident response is iterative.
Your framework should be too.
Free for you to read, share, and adapt under CC BY 4.0. No purchase, no login.