Incident Response Flashcards
IR Process
Preparation
Detection
Analysis
Containment
Eradication/Recovery
Post-incident Activity
Preparation
“Proactive”
What are the key ingredients of the Preparation step?
Plan
Properly trained staff
Forensics Hardware and Software
Regular exercises/practice
Detection
Start of the reactive part of the process
What ways can you detect?
Endpoint Detection and Response
Security Information and Event Management
Your own users
ISPs
Law Enforcement
What is EDR?
Endpoint Detection and Response
What is SIEM?
Security Information and Event Management
Analysis
Collecting
- Memory
- Log/Registry Files
- Network Activity
- Disk images
What is the goal of Analysis
Determine the root cause of the incident and reconstruct actions of the threat actor.
Containment
How do you stop the threat actor from compromising other network resources?
What is the average eCrime breakout time?
1h 24m
1-10-60 rule
Detecting, understanding, containing
Eradication and Recovery
Removing things from the system and restoring data from backups.
Which is easier, reimaging a system or cleaning it?
Reimaging
Post incident activity
Lessons learned
Written Report