Skip to content
Respond

Contain the Incident - Automatically or Behind an Approval Gate

Isolate the device, kill the process, expire the credential - with full audit trails, SOAR-lite playbooks, and separation of duties on everything sensitive.

Response Actions

The Actions That End an Incident

Every action carries an audit trail from the moment it is requested to the moment it completes.

ActionEffect
Isolate deviceCut the endpoint off from the network while you investigate
Release isolationReturn the endpoint to normal operation
Kill processTerminate a specific process
Expire credentialKill a leaked credential server-side - no device required
Playbooks

Bind a Trigger to an Ordered Set of Actions

A playbook binds a trigger pattern to an ordered list of response actions. Each playbook either auto-executes or files its actions for human approval, so containment speed and human judgment are a configuration choice rather than an architectural one.

Every firing is recorded as a run with the triggering context - alert ID, summary, device - and a status of executed, approval pending, or failed. Run counts and last-run timestamps are tracked per playbook.

Approvals

Separation of Duties, Enforced

  • Enforcement policies, response actions, and evidence attestation can each be gated behind human approval
  • The requester cannot approve their own request - separation of duties is enforced by the platform, not by convention
  • Approval decisions land in the append-only audit log with user, action, resource, and timestamp
Quarantine

Detected Threats, Safely Held

  • Quarantined files are held encrypted (AES-256), unable to execute or spread
  • Administrators review, restore, or permanently delete quarantined files from the dashboard
  • Sample upload supports controlled retrieval for analysis
Containment menu on a device offering isolate device, kill process, and expire credential
Containment actions on a device: isolate, kill process, expire credential.
New playbook dialog with trigger source, minimum severity, an ordered action list, and an auto-execute toggle
Playbook builder - bind a trigger to an ordered chain of containment actions, then auto-execute or queue for human approval.
Compliance

Controls This Pillar Satisfies

NIST IR-6
Incident reporting with recorded response actions and outcomes
SOC 2 CC7.3
Evaluation of security events and the response taken
ISO A.8.15
Logging - append-only audit trail of administrative actions
NIST AC-6
Least privilege - separation of duties on sensitive actions

See Kraitos AIDR in Action

Deploy in 60 seconds. Get answers in 24 hours. Stop guessing what your AI-augmented organization is doing.

[email protected]kraitos.io