ArcanaIncident-response documentationBrowse the feedTemplates
Back to feed
Runbook · Triage
RB-TRIAGE-007

Active Exploitation Validation

1. Prerequisites

  • Exploitation alert or notification received
  • Access to SIEM
  • Access to EDR platform
  • Access to IDS/IPS telemetry
  • Access to vulnerability management platform
  • Access to threat intelligence sources
  • Access to affected asset information
  • Incident ticket created

2. Step-by-Step Instructions

  1. Review Initial Alert

    • Identify:
      • Alert source
      • Detection type
      • Timestamp
      • Affected assets
    • Record findings.
  2. Identify Exploitation Indicators

    • Review:
      • Exploit signatures
      • Process execution
      • Network activity
      • Authentication activity
    • Document indicators.
  3. Validate Asset Exposure

    • Confirm:
      • Asset existence
      • Asset ownership
      • Service exposure
      • Vulnerability status
    • Document findings.
  4. Review Threat Intelligence

    • Determine:
      • Known exploitation activity
      • Exploit availability
      • Active campaigns
    • Record relevant intelligence.
  5. Review Endpoint Activity

    • Review:
      • Process execution
      • Child processes
      • Command execution
      • Persistence activity
    • Identify evidence of exploitation.
  6. Review Network Activity

    • Identify:
      • Inbound connections
      • Outbound connections
      • C2 activity
      • Lateral movement indicators
    • Document findings.
  7. Assess Exploitation Status

    • Determine:
      • Attempted exploitation
      • Successful exploitation
      • Ongoing exploitation
    • Document confidence level.
  8. Assess Immediate Risk

    • Determine:
      • Number of assets affected
      • Business impact
      • Exposure level
    • Assign preliminary severity.
  9. Document Findings

    • Record:
      • Indicators observed
      • Assets involved
      • Severity assessment
      • Confidence level
    • Preserve supporting evidence.
  10. Escalate and Hand Off

    • Escalate confirmed activity for investigation and containment.
    • Update the incident record with all findings.

3. Post-Action

  • Ensure findings are documented.
  • Preserve evidence supporting validation.
  • Record affected assets and indicators.
  • Ensure appropriate escalation has occurred.

Contributor

Vishal Thakur GitHub: https://github.com/malienist

Contributed to the Arcana Incident Response Documentation Framework.