On November 2, 1988, a graduate student's experiment knocked out roughly a tenth of the internet in a single night. The response was improvised over phone lines and hallway meetings — and nearly everything modern incident response does today was invented in those 72 hours.
Incident-Response
-
The Morris Worm: The Internet's First Incident Response -
Digital Forensics and Memory Analysis A practitioner's guide to DFIR methodology: capturing volatile evidence in the correct order, imaging disks and memory without corrupting them, and turning a Volatility 3 memory dump and a plaso super-timeline into a defensible incident narrative.
-
Incident Response Automation: Self-Healing Infrastructure with AWS, Ansible, and Observable Feedback Loops A deep technical guide to building automated incident response pipelines with AWS Systems Manager Automation runbooks, EventBridge-triggered remediation, Lambda auto-remediation patterns, Ansible for incident response, and self-healing infrastructure with observable feedback loops.
-
The On-Call Handbook: Rotations, Runbooks, and Recovering Without Burning Out A comprehensive guide to sustainable on-call—covering rotation design, escalation paths, writing runbooks that actually work, alert hygiene, incident management, postmortems, and protecting engineers from burnout.
-
Incident Response Playbook A practical incident response playbook covering detection, triage, containment, eradication, recovery, and blameless postmortems — with templates, runbooks, and communication scripts you can adapt for your team.