1. Prerequisites
- Exploitation alert or notification received
- Access to SIEM
- Access to EDR platform
- Access to IDS/IPS telemetry
- Access to vulnerability management platform
- Access to threat intelligence sources
- Access to affected asset information
- Incident ticket created
2. Step-by-Step Instructions
-
Review Initial Alert
- Identify:
- Alert source
- Detection type
- Timestamp
- Affected assets
- Record findings.
- Identify:
-
Identify Exploitation Indicators
- Review:
- Exploit signatures
- Process execution
- Network activity
- Authentication activity
- Document indicators.
- Review:
-
Validate Asset Exposure
- Confirm:
- Asset existence
- Asset ownership
- Service exposure
- Vulnerability status
- Document findings.
- Confirm:
-
Review Threat Intelligence
- Determine:
- Known exploitation activity
- Exploit availability
- Active campaigns
- Record relevant intelligence.
- Determine:
-
Review Endpoint Activity
- Review:
- Process execution
- Child processes
- Command execution
- Persistence activity
- Identify evidence of exploitation.
- Review:
-
Review Network Activity
- Identify:
- Inbound connections
- Outbound connections
- C2 activity
- Lateral movement indicators
- Document findings.
- Identify:
-
Assess Exploitation Status
- Determine:
- Attempted exploitation
- Successful exploitation
- Ongoing exploitation
- Document confidence level.
- Determine:
-
Assess Immediate Risk
- Determine:
- Number of assets affected
- Business impact
- Exposure level
- Assign preliminary severity.
- Determine:
-
Document Findings
- Record:
- Indicators observed
- Assets involved
- Severity assessment
- Confidence level
- Preserve supporting evidence.
- Record:
-
Escalate and Hand Off
- Escalate confirmed activity for investigation and containment.
- Update the incident record with all findings.
3. Post-Action
- Ensure findings are documented.
- Preserve evidence supporting validation.
- Record affected assets and indicators.
- Ensure appropriate escalation has occurred.
Contributor
Vishal Thakur GitHub: https://github.com/malienist
Contributed to the Arcana Incident Response Documentation Framework.
