ArcanaIncident-response documentationBrowse the feedTemplates
Back to feed
Runbook · Contain
RB-CONTAIN-012

Exploitation Surface Containment

1. Prerequisites

  • Confirmed exploitation activity
  • Completion of exploitation analysis
  • Access to affected systems
  • Access to firewall administration
  • Access to cloud administration
  • Access to vulnerability management platform
  • Approval for containment actions where required

2. Step-by-Step Instructions

  1. Identify Exploited Assets

    • Confirm affected systems.
    • Document exploitation vector.
  2. Identify Exposure Path

    • Determine:
      • Internet-facing services
      • Vulnerable applications
      • Misconfigurations
    • Document findings.
  3. Restrict External Access

    • Restrict:
      • Internet exposure
      • Public access
      • Unnecessary network paths
    • Validate restrictions.
  4. Disable Vulnerable Services

    • Disable:
      • Vulnerable services
      • Affected applications
      • Exposed interfaces
    • Document actions.
  5. Apply Temporary Mitigations

    • Implement:
      • Firewall rules
      • WAF rules
      • Network restrictions
      • Access controls
    • Validate deployment.
  6. Restrict Administrative Access

    • Limit:
      • Administrative access
      • Remote management access
      • Third-party access
    • Document changes.
  7. Monitor for Continued Activity

    • Review:
      • Exploitation attempts
      • Access attempts
      • Network activity
    • Escalate continued activity.
  8. Validate Containment

    • Confirm:
      • Exposure paths removed
      • Vulnerable services restricted
      • Exploitation activity ceased
    • Document validation.
  9. Document Containment Actions

    • Record:
      • Systems affected
      • Controls implemented
      • Validation results
    • Preserve evidence.
  10. Escalate and Hand Off

    • Provide containment status to the Incident Commander.
    • Coordinate recovery and remediation activities.
    • Update the incident record.

3. Post-Action

  • Ensure all containment actions are documented.
  • Preserve evidence supporting containment.
  • Record outstanding remediation actions.
  • Participate in recovery activities.

Contributor

Vishal Thakur GitHub: https://github.com/malienist

Contributed to the Arcana Incident Response Documentation Framework.