1. Prerequisites
- Authentication telemetry
- Identity provider logs
- User reports
- Browser telemetry
- Threat intelligence data
- Endpoint telemetry
- Identity provider access
- SIEM platform access
- EDR platform access
- Threat intelligence platform access
- Password exposure monitoring tools
2. Step-by-Step Instructions
-
Identify Initial Exposure Vector
- Determine whether exposure occurred through:
- Phishing
- Malware
- Credential stuffing
- Password reuse
- Browser credential theft
- Token theft
- Public credential leaks
- Determine whether exposure occurred through:
-
Review Authentication Timeline
- Identify:
- Earliest suspicious login
- Failed authentication attempts
- MFA activity
- Password reset activity
- Session creation activity
- Identify:
-
Assess Password Reuse Risk
- Determine:
- Shared password usage
- Corporate/personal password overlap
- Service account reuse
- Administrative credential reuse
- Determine:
-
Review Endpoint Exposure Indicators
- Identify:
- Browser credential dumping
- Token theft
- Session cookie theft
- Password manager compromise
- Infostealer activity
- Identify:
-
Review External Exposure Sources
- Check:
- Credential dump repositories
- Threat intelligence feeds
- Dark web monitoring sources
- Known breach datasets
- Check:
-
Identify Adjacent Risk
- Assess:
- Additional affected accounts
- Shared devices
- Shared authentication infrastructure
- Shared API credentials
- Assess:
3. Post-Action
- Document all findings within the incident ticket
Contributor
Vishal Thakur
GitHub: https://github.com/malienist
Jayden Vo GitHub: https://github.com/jayden-vo
Contributed to the Arcana Incident Response Documentation Framework.
