1. Prerequisites
- Confirmed exploitation activity
- Access to SIEM
- Access to EDR
- Access to asset inventory
- Access to authentication logs
- Access to network telemetry
2. Step-by-Step Instructions
-
Identify Initial Affected Asset
- Confirm the originally affected system.
- Document ownership and business function.
-
Review Related Connections
- Review:
- Network communications
- Authentication relationships
- Administrative access
- Identify related assets.
- Review:
-
Identify Additional Hosts
- Search for:
- Similar indicators
- Similar activity
- Related communications
- Document findings.
- Search for:
-
Review Authentication Activity
- Identify:
- Shared accounts
- Administrative access
- Lateral movement indicators
- Document findings.
- Identify:
-
Review Cloud and SaaS Activity
- Identify:
- Connected assets
- Cloud resources
- SaaS resources
- Document findings.
- Identify:
-
Review Asset Inventory
- Identify:
- Asset owners
- Business units
- Criticality ratings
- Document findings.
- Identify:
-
Correlate Findings
- Correlate:
- Endpoint telemetry
- Authentication activity
- Network activity
- Determine full affected scope.
- Correlate:
-
Assess Business Impact
- Identify:
- Critical systems
- Production systems
- Sensitive environments
- Document impact.
- Identify:
-
Create Asset Inventory
- Record:
- Hostnames
- IP addresses
- Asset owners
- Business criticality
- Finalise affected asset list.
- Record:
-
Escalate and Hand Off
- Provide findings to containment and recovery teams.
- Update the incident record.
3. Post-Action
- Ensure affected asset inventory is complete.
- Preserve evidence supporting asset identification.
- Attach asset inventory to the incident record.
Contributor
Vishal Thakur GitHub: https://github.com/malienist
Contributed to the Arcana Incident Response Documentation Framework.
