Shift Handover Template
CONFIDENTIAL Do not share this protocol with other people. Content might include sensitive information.
CAUTION Don't click any of the listed links in this protocol, except the ones explicitly marked as safe.
π
Administrative
- Who was working and who is next?
- What does the schedule look like for the next couple of weeks?
|
OnCall |
Helpers |
Previous |
|
|
New |
|
|
π‘οΈ Detection
- What detections have been written/updated/refactored?
- What False Positive Allowlisting has been done?
π±βπ» Automation
- What automation has been built/updated/refactored? Any Cortex Responders or Analysers?
π‘ Notable events, results from daily checks, new vulnerabilities, patches, exploits, attacksβ¦
Day |
Description |
Friday |
For each case: title, reference and a short summary |
Weekend |
|
Monday |
|
Tuesday |
|
Wednesday |
|
Thursday |
|
Friday |
|
π οΈ Maintenance and the like that may affect us / our systems
- Any maintenance announcements for the system we rely on?
π§ͺ Pentest Announcements
Indicator(s) |
Timeframe(s) |
Targets(s) |
Environment(s) |
Contact(s) |
|
|
|
|
|
π Recommended Readings (Links in this section are safe to click)
Title |
Description |
Recommended by |
Link |
|
|
|
|
π Metrics
- Number of cases in the past 8 days
- Cases in from previous shifts, but still open
- Average case handling time per severity level (Low, Medium, High, Critical)
- Number of cases which are a true positive with impact
- Overview of the most frequent detections
Relevant Note(s): Incident Response