1. Prerequisites
- PIR findings
- Detection gaps
- TTP mapping report
- Recovery lessons learned
- Executive recommendations
- Access to SIEM
- Access to EDR platform
- Access to vulnerability management platform
- Access to identity management platform
- Access to network security tooling
2. Step-by-Step Instructions
-
Review Root Cause & Control Failures
- Identify:
- Initial access failures
- Detection failures
- Containment weaknesses
- Recovery bottlenecks
- Identify:
-
Improve Detection Coverage
- Implement:
- New detection logic
- Enhanced telemetry collection
- Improved alert tuning
- Additional hunt content
- Implement:
-
Harden Identity Infrastructure
- Review:
- Privileged access
- MFA coverage
- Service accounts
- Administrative segmentation
- Review:
-
Improve Network Segmentation
- Enhance:
- East-west restrictions
- Administrative isolation
- Backup network isolation
- Critical infrastructure separation
- Enhance:
-
Strengthen Backup Security
- Implement:
- Immutable backups
- Offline recovery capability
- Backup monitoring
- Backup access restrictions
- Implement:
-
Conduct Lessons Learned Review
- Document:
- What worked well
- What failed
- Process improvements
- Tooling improvements
- Document:
3. Post-Action
- Ensure that improvements made are documented and tracked
- Recording findings from the Lessons Learned Review into the PIR document
Contributor
Vishal Thakur
GitHub: https://github.com/malienist
Jayden Vo GitHub: https://github.com/jayden-vo
Contributed to the Arcana Incident Response Documentation Framework.
