1. Prerequisites
- Confirmed exploitation activity
- Completion of exploitation analysis
- Access to affected systems
- Access to firewall administration
- Access to cloud administration
- Access to vulnerability management platform
- Approval for containment actions where required
2. Step-by-Step Instructions
-
Identify Exploited Assets
- Confirm affected systems.
- Document exploitation vector.
-
Identify Exposure Path
- Determine:
- Internet-facing services
- Vulnerable applications
- Misconfigurations
- Document findings.
- Determine:
-
Restrict External Access
- Restrict:
- Internet exposure
- Public access
- Unnecessary network paths
- Validate restrictions.
- Restrict:
-
Disable Vulnerable Services
- Disable:
- Vulnerable services
- Affected applications
- Exposed interfaces
- Document actions.
- Disable:
-
Apply Temporary Mitigations
- Implement:
- Firewall rules
- WAF rules
- Network restrictions
- Access controls
- Validate deployment.
- Implement:
-
Restrict Administrative Access
- Limit:
- Administrative access
- Remote management access
- Third-party access
- Document changes.
- Limit:
-
Monitor for Continued Activity
- Review:
- Exploitation attempts
- Access attempts
- Network activity
- Escalate continued activity.
- Review:
-
Validate Containment
- Confirm:
- Exposure paths removed
- Vulnerable services restricted
- Exploitation activity ceased
- Document validation.
- Confirm:
-
Document Containment Actions
- Record:
- Systems affected
- Controls implemented
- Validation results
- Preserve evidence.
- Record:
-
Escalate and Hand Off
- Provide containment status to the Incident Commander.
- Coordinate recovery and remediation activities.
- Update the incident record.
3. Post-Action
- Ensure all containment actions are documented.
- Preserve evidence supporting containment.
- Record outstanding remediation actions.
- Participate in recovery activities.
Contributor
Vishal Thakur GitHub: https://github.com/malienist
Contributed to the Arcana Incident Response Documentation Framework.
