Endpoint Incident Response Checklist Form
Complete this checklist to ensure all critical steps of endpoint incident response are properly documented and executed.
Incident Identifier
*
Date and Time of Incident Detection
*
 -
Month
 -
Day
Year
2 digit month, 2 digit day, 4 digit year
Date
Hour Minutes
AM
PM
AM/PM Option
Affected Endpoint (Hostname or Asset Tag)
*
Initial Incident Classification Completed
*
Yes, initial classification is complete
Endpoint Isolated from Network
*
Endpoint has been isolated
Malicious Processes Terminated
*
Malicious processes terminated
Forensic Evidence Collected
*
Forensic evidence collected
Malware or Indicators of Compromise Removed
*
Malware/IOC removed
Endpoint Restored and Patched
*
Endpoint restored and patched
Summary of Actions Taken and Next Steps
*
Submit Checklist
Should be Empty: