1. Prerequisites
- Backup platform access (logs, configuration, inventory, immutable storage settings)
- Access to the relevant backup target platforms (cloud storage, virtualisation, file systems)
- Identity and authentication logs for backup admin accounts (to assess exposure)
- Isolated test environment for controlled restoration tests
- Malware scanning capability for validating restored data
2. Step-by-Step Instructions
-
Identify Backup Infrastructure Exposure
- Determine:
- Backup servers impacted
- Backup credentials exposed
- Administrative access abuse
- Backup network exposure
- Determine:
-
Review Backup Activity Logs
- Check for:
- Backup deletion attempts
- Retention policy changes
- Immutable storage tampering
- Failed backup jobs
- Check for:
-
Validate Backup Availability
- Confirm:
- Recovery points exist
- Offline backups available
- Immutable backups intact
- Replication status healthy
- Confirm:
-
Perform Controlled Restoration Tests
-
Restore:
- Sample files
- Critical systems
- Test workloads
-
Validate:
- File integrity
- Malware absence
- System functionality
-
-
Identify Recovery Constraints
- Determine:
- Recovery time estimates
- Resource bottlenecks
- Infrastructure dependencies
- Restoration sequencing requirements
- Determine:
3. Post-Action
- Document all findings within the incident ticket
Contributor
Vishal Thakur
GitHub: https://github.com/malienist
Jayden Vo GitHub: https://github.com/jayden-vo
Contributed to the Arcana Incident Response Documentation Framework.
