1. Prerequisites
- Authentication logs access
- MFA logs access
- VPN logs access
- Session telemetry data
- Conditional access logs
- Identity provider access
- SIEM platform access
- MFA platform access
- Threat intelligence platform access
2. Step-by-Step Instructions
-
Build Authentication Timeline
- Identify
- Earliest suspicious login
- Successful authentications
- Failed login attempts
- MFA activity
- Session creation events
- Identify
-
Review Source Infrastructure
- Assess:
- Source IPs
- ASN/provider
- Geolocation
- Is Known malicious infrastructure
- VPN or anonymisation usage
- Assess:
-
Analyse Device & Session Context
- Review:
- Device identifiers
- Browser fingerprints
- Session duration
- User-agent strings
- New device registrations
- Review:
-
Review MFA Activity
- Identify:
- MFA fatigue attempts
- Push bombing
- MFA bypass
- Device registration anomalies
- Failed MFA attempts
- Identify:
-
Assess Privileged Activity
- Review:
- administrative logins
- privileged role usage
- sensitive application access
- unusual administrative actions
- Review:
-
Correlate Additional Activity
- Review:
- Endpoint telemetry
- VPN access
- SaaS access
- Cloud activity
- Lateral movement indicators
- Review:
3. Post-Action
- Document all investigation findings within the incident ticket
Contributor
Vishal Thakur GitHub: https://github.com/malienist
Jayden Vo GitHub: https://github.com/jayden-vo
Contributed to the Arcana Incident Response Documentation Framework.
