New learner
Do not start here
Runbooks assume you know the basic vocabulary. Start with Learn or Coach first.
Runbook Index
Use this page when you know the situation but want a clear route through triage, evidence, handoff, tracking, and reporting without guessing which page comes next.
Pick A Runbook Level
Runbooks are for repeatable work. If you are learning, use Learn or Coach first. If you are responding, start with the situation that is closest.
New learner
Runbooks assume you know the basic vocabulary. Start with Learn or Coach first.
Daily work
Best when you need a calm morning routine for current vulnerability pressure.
Incident-like pressure
Best when exploitation, exposure, public PoC, or owner urgency is driving the day.
Site/app cleanup
Best when the work is QA, generated artifacts, app contract, release health, or content governance.
Runbook rule: start with the smallest path that answers the decision. Open deeper pages only when you need proof, owner handoff, detection support, or leadership reporting.
Runbooks
8situation-first paths for common workWorkflow lanes
8shared intake-to-reference route mapCadences
4daily, weekly, incident, monthly rhythmsOwners
5patch, SOC, asset, risk, leadershipOutput
Cleardecision, evidence, ticket, brief, reviewRunbook Or Workflow
Use this index when the problem already has a shape: urgent CVE, patch blocked, scanner noise, SOC request, leadership update, training session, program improvement, or data trust question.
Use Workflows when you want to move through intake, validation, decision, action, communication, governance, practice, or reference without memorizing page names.
Use Search when you only know a CVE, vendor, source, product, weak signal, or phrase. Search now marks lane-aware page results where a workflow fit is known.
By Situation
Exploited or urgent CVE
Use this when a KEV, public PoC, ransomware-relevant, or internet-facing item needs a calm but fast decision.
Patch blocked
Use this when there is no patch, unclear vendor guidance, risky change timing, or an exception request.
Scanner or false-positive noise
Use this when a scanner finding, CPE match, stale scan, backport, feature-state claim, or not-affected request needs proof before action.
SOC request
Use this when analysts need indicators, telemetry ideas, Sigma drafts, or quick hunt query starting points.
Leadership update
Use this when the audience needs business-readable posture, not raw CVE detail or noisy analyst notes.
Program improvement
Use this after busy triage periods to identify whether the weak link was ownership, evidence, telemetry, communication, follow-up, or release-health review.
Training or app review
Use this when the goal is onboarding, role practice, game content QA, Android WebView review, or a local progress report rather than live remediation work.
Trust or data issue
Use this when a count looks stale, a source looks weak, a page is blank, generated artifacts need review, or a user asks why the portal recommends a path.
By Cadence
Briefing Room, Defenders Today, KEV, and Saved. Output: top decisions, immediate blockers, and owners.
Coach, Daily Challenge, Guided Practice, and Practice Report. Output: one safe practice route, local progress, and a next learning target.
Patch Watch, Patch Window, Exception Register, Vendor Analytics, and Action Tracker. Output: patch plan, blockers, and time-bound exceptions.
Decision Matrix, Evidence Checklist, Detection Starter Pack, Handoff Center, and Status. Output: fast owner-aligned actions.
Operational Readiness, Maturity Model, Quality Center, Status static health, Coverage Map, and Release Notes. Output: one focused improvement batch with release-health evidence.
By Output
Patch now, patch soon, mitigate first, detect, validate, monitor, escalate, or accept. Use Decision Matrix.
A compact proof set for exposure, affected version, source confidence, fixed version, and owner context. Use Evidence Checklist.
A short copy-ready message for patch, SOC, asset, risk, vendor, or leadership owner. Use Stakeholder Matrix and Handoff Center.
A saved item with state, note, owner, deadline, review date, closure evidence, and evidence-quality grade. Use Saved, Action Tracker, Remediation Evidence, and Evidence Quality.
A plain-English update about what changed, what is owned, what is blocked, and what decision is needed. Use Brief Builder.
A browser-local summary of practice runs, guided routes, focus lanes, badges, and next recommendation. Use Practice Report.
A focused quality or maturity action that prevents the same problem next time. Use Quality Center, Status static health, the release-health brief, and Maturity Model.
Best next move: if you are unsure where to begin, open Daily Workflow for today, Scenario Library for the situation, Coach for safe practice, or Quality Center if the site itself needs tightening.