1. Prerequisites
- EDR alerts
- Endpoint telemetry
- Process execution data
- File hashes
- User and host information
- Threat intelligence enrichment
Required Tools:
- EDR platform
- SIEM
- Threat intelligence platform
- Asset inventory
- Authentication telemetry
2. Step-by-Step Instructions
Common Failure Modes
- Treating behavioural detections as false positives too early
- Ignoring blocked malware activity
- Failing to assess broader scope
-
Validate Alert Authenticity
- Determine:
- Alert source
- Detection type
- Confidence level
- Whether detection is prevention or detection only
Review: - Detection signatures - Behavioural indicators - Alert metadata
- Determine:
-
Identify Impacted Endpoint
- Collect:
- Hostname
- IP address
- Logged-in user
- Device criticality
- Operating system
- Business owner
- Collect:
-
Review Malware Indicators
- Identify:
- File hashes
- Process names
- Command-line arguments
- Parent-child process chains
- Network connections
- Identify:
-
Assess Execution Status
- Determine:
- Was malware blocked?
- Was execution successful?
- Is malware still active?
- Did persistence occur?
- Determine:
-
Assess Potential Scope
- Review:
- Similar detections across environment
- Same hash/process activity
- Shared user activity
- Shared infrastructure usage
- Review:
-
Determine Severity
- Assess:
- Malware capability
- Credential theft potential
- Lateral movement indicators
- Persistence mechanisms
- Critical system involvement
- Assess:
3. Post-Action
- Ensure all analysed headers, extracted IOCs, and initial verdict are documented in the incident ticket
Contributor
Vishal Thakur GitHub: https://github.com/malienist
Jayden Vo GitHub: https://github.com/jayden-vo
Contributed to the Arcana Incident Response Documentation Framework.
