Incident-Response Containment Runbook
Detect → grade → do the recovery.
AgentSmack's Containment lens grades recoverability — the MTTR verdict, the score, the footholds to evict, the irreversible damage already done. But grading stops one step short of what an IR team actually runs. This is the operational producer companion: the prioritized, deduplicated, dependency-ordered containment runbook a SOC executes after a red-team — isolate the poisoned session FIRST, revoke the over-granted scope, evict planted footholds, reverse executed actions, rotate exfiltrated data, and rebuild telemetry trust LAST — each step with an explicit verification check, plus a residual-containment-risk trajectory showing how the IR posture recovers as each phase is executed. It re-authors nothing: the containment grade, footholds, and irreversible reach are inherited verbatim from the containment grader, so the closed vocabulary cannot drift. The residual floor is sticky — an unrecoverable run (irreversible damage + a suppressed trail) cannot trajectory or budget its way down to fully clean — and honest-empty: a run that never reached a foothold reports no incident, never a fabricated recovery step. It adds no new surface and no new scorecard dimension. Fill with a sample run to watch the runbook order itself and the residual curve recover with no live infra.
Related read-only blue-team meta-lenses over the same findings envelope: Containment / Recoverability (MTTR) · Attack-Path / Kill-Chain Correlation · Detectability / Dwell-Time (MTTD).