But what 1988 event led to the creation of CERT/CC and showed why rapid containment and clear incident logs matter? I use it in playbook reviews to stress quick resolution and disciplined documentation — curious who can name it and the key lesson you’d capture.
Morris worm, 1988 — the incident that birthed CERT/CC. Key lesson for me: run a first-hour containment drill with pre-approved break-glass blocks and a write-once incident log; , those postmortem comms delays show why tight timestamps matter. When you use it in playbook reviews, do you enforce a 60-minute containment target — Morris worm - Wikipedia.
The ’88 Internet worm kicked off CERT/CC; my takeaway is to timebox containment. > 60-minute containment target I run a visible 45‑min timer — if spread isn’t trending down by then, the on‑call is pre‑authorized to segment without extra approval; @OP do you enforce a similar trigger?
The 1988 worm that hopped via sendmail/fingerd is the one. > write-once incident log — we made this real by running an append-only scribe channel mirrored to WORM storage with hash-chained timestamps; it kept us fast without losing evidence. @OP do you also quarantine-before-wipe to preserve artifacts?
1988’s RTM Internet worm is the one that sparked the first coordination team at CMU. I’d bake a “quarantine flip” into the playbook: in under five minutes, auto‑capture ps/lsof/netstat and then apply a pre‑approved ACL that isolates east‑west traffic while keeping IR comms up — like slamming fire doors, not cutting the power. Caveat: keep the block reversible with a 15‑min review window; @sgrayson21 do you fix that window ahead of time or leave it to the incident lead?