AI Playbook

Compromised-account investigation

Investigate a suspected identity compromise and prepare evidence-backed containment options.

Copy this prompt

Replace the bracketed values, then paste it into an AI client connected to Stackyapper.

Run the "Compromised-account investigation" playbook using Stackyapper.

Inputs
- user: [Suspected compromised identity]
- time window: [Optional bounded investigation window] (optional)
- indicator: [Optional alert, IP, application, or observed behavior] (optional)

Objective
Investigate a suspected identity compromise and prepare evidence-backed containment options.

Required evidence
- Identity security

Use when available
- User directory
- Mailbox settings
- Groups and access
- Directory devices
- Security findings
- Service tickets
- Documentation

Procedure
1. Collect relevant identity alerts, incidents, and sign-in evidence.
2. Review current account, mailbox, group, and device context for suspicious changes.
3. Correlate other security findings, tickets, and approved incident runbooks.
4. Separate confirmed indicators from suspicion and propose containment steps requiring approval.

Return
- Incident timeline
- Indicators and evidence
- Affected scope
- Severity and confidence
- Containment and recovery plan

Use only evidence available through the Stackyapper Apps and permissions connected to this AI client. If required evidence is unavailable, say what is missing before continuing. Do not guess or make changes in connected systems.

Before you paste

Replace every bracketed value in the prompt. Delete an optional input line if it does not apply.

  • user: Suspected compromised identity. (required)
  • time window: Optional bounded investigation window. (optional)
  • indicator: Optional alert, IP, application, or observed behavior. (optional)

What Stackyapper will use

The exact tools depend on the Apps connected to your workspace and the current user's permissions.

  • Identity security (required)
  • User directory (used when available)
  • Mailbox settings (used when available)
  • Groups and access (used when available)
  • Directory devices (used when available)
  • Security findings (used when available)
  • Service tickets (used when available)
  • Documentation (used when available)

What you'll get

  • Incident timeline
  • Indicators and evidence
  • Affected scope
  • Severity and confidence
  • Containment and recovery plan

How it works

  1. Collect relevant identity alerts, incidents, and sign-in evidence.
  2. Review current account, mailbox, group, and device context for suspicious changes.
  3. Correlate other security findings, tickets, and approved incident runbooks.
  4. Separate confirmed indicators from suspicion and propose containment steps requiring approval.