1. Prerequisites
Before starting this runbook, ensure the following:
- DDoS incident has been resolved
- Service restoration activities have been completed
- Incident timeline has been documented
- Relevant stakeholders are available
- Technical evidence has been preserved
- Incident ticket remains active
- Post-incident review has been scheduled
2. Step-by-Step Instructions
-
Conduct Post-Incident Review
Review:
- Incident timeline
- Detection timeline
- Escalation timeline
- Mitigation timeline
- Recovery timeline
- Communications timeline
Identify:
- What worked well
- What did not work well
- Areas for improvement
Document findings.
-
Assess Detection Effectiveness
Review:
- Alert generation
- Alert quality
- Alert timing
- Monitoring coverage
- Escalation effectiveness
Determine:
- Detection gaps
- Visibility gaps
- Alert tuning opportunities
Document findings.
-
Assess Mitigation Effectiveness
Review:
- CDN protections
- WAF protections
- DDoS mitigation services
- ISP support
- Traffic filtering controls
- Rate limiting controls
Determine:
- Controls that were effective
- Controls that were ineffective
- Additional controls required
Document findings.
-
Review Infrastructure Resilience
Assess:
- Network capacity
- Load balancer capacity
- Cloud scaling effectiveness
- CDN performance
- Application resilience
- Service redundancy
- Geographic resilience
Identify infrastructure improvements.
Document findings.
-
Review Provider Performance
Assess:
- CDN provider response
- Cloud provider response
- ISP support effectiveness
- DDoS provider effectiveness
- Third-party response times
Identify:
- Vendor strengths
- Vendor weaknesses
- Contractual improvement opportunities
Document findings.
-
Review Business Impact
Assess:
- Customer impact
- Revenue impact
- Operational disruption
- SLA impact
- Reputational impact
- Executive impact
Document business consequences.
Identify opportunities to reduce future impact.
-
Identify Security Improvements
Review opportunities to improve:
- DDoS detection
- Traffic visibility
- Threat intelligence integration
- Network segmentation
- WAF protections
- Bot management
- Incident response procedures
Document recommendations.
-
Update Documentation
Review and update:
- Playbooks
- Runbooks
- SOPs
- Escalation procedures
- Contact lists
- Architecture documentation
Ensure documentation reflects lessons learned.
Document updates performed.
-
Create Improvement Plan
Develop an action plan containing:
- Improvement activities
- Owners
- Priority levels
- Due dates
- Success criteria
Track actions through completion.
Document the plan.
-
Update Incident Record
Record:
- Review findings
- Detection improvements
- Mitigation improvements
- Infrastructure improvements
- Vendor observations
- Documentation updates
- Improvement plan
Attach supporting evidence.
3. Post-Action
Upon completion:
- Ensure post-incident review findings are documented
- Ensure improvement opportunities are identified
- Ensure documentation updates are completed
- Ensure action items have owners assigned
- Ensure supporting evidence is attached
- Ensure incident ticket is updated or formally closed
Contributor
Vishal Thakur GitHub: https://github.com/malienist
Contributed to the Arcana Incident Response Documentation Framework.
