Module 03
Incident Response
CYBERPRO Israel© Copyright | Do not distribute without written permission
[Link]
b002013c6ad0
Program
▪ What is an Incident?
▪ Incident Response Team
▪ Incident Response NIST 800-61
▪ Incident Response Systems
CYBERPRO Israel© Copyright | Do not distribute without written permission
[Link]
b002013c6ad0
Learning Objectives
▪ You will be able to respond properly to a cybersecurity incident
▪ You will be able to explain the importance of NIST 800-61
CYBERPRO Israel© Copyright | Do not distribute without written permission
[Link]
b002013c6ad0
Incident Response
CYBERPRO Israel© Copyright | Do not distribute without written permission
[Link]
b002013c6ad0
Why is it important to respond to incidents as fast as
possible?
CYBERPRO Israel© Copyright | Do not distribute without written permission
[Link]
b002013c6ad0
Which unit in the company would be involved in the
response process?
CYBERPRO Israel© Copyright | Do not distribute without written permission
[Link]
b002013c6ad0
Incident Response
• Covering all aspects of the incident response (managerial, judicial, public affairs, etc.)
• Built-in organizational access for quick and efficient response.
• Narrow the company’s downtime to the minimum possible.
• Reestablish normal operations as soon as possible, closing breaches and minimizing
damages.
• Compatibility with regulatory demands and response escalation with official representatives
(police, the private sector of cyber, banking regulators, etc.)
CYBERPRO Israel© Copyright | Do not distribute without written permission
[Link]
b002013c6ad0
Incident Response Team
• A designated team designed to respond to cyber incidents in a swift and efficient manner.
The team can be from the organization or be an external service.
• A systematic and uniform response - Incident Response Plan document.
The response team is the leading authority to determine the organizational response policy.
• Minimize or prevent loss/corruption of data.
The team will handle any suspicious activity from any origin such as workstations/network / technical malfunctions.
• Use collected data for research and preparation for future incidents.
CYBERPRO Israel© Copyright | Do not distribute without written permission
[Link]
b002013c6ad0
National Institute of Standards and Technology (NIST)
● An institute meant to set industry standards to enhance the US economy and safeguard the American
lifestyle.
● NIST is a sub-department managed by the US Department of commerce but is not regulatory (no
obligation to comply with the set standards).
● NIST gives instructions and regulations on the topic of technology and data security:
○ Incident Response – 800-61 NIST
○ Disaster Recovery - NIST 800-184
○ Data Management - NIST SP 800-171
CYBERPRO Israel© Copyright | Do not distribute without written permission
[Link]
b002013c6ad0
National Institute of Standards and Technology (NIST)
[Link]
CYBERPRO Israel© Copyright | Do not distribute without written permission
[Link]
b002013c6ad0
Incident Response Plan
Lessons
Preparation Identification Containment Eradication Recovery
Learned
CYBERPRO Israel© Copyright | Do not distribute without written permission
[Link]
b002013c6ad0
Preparation Stage
CYBERPRO Israel© Copyright | Do not distribute without written permission
[Link]
b002013c6ad0
Stage 1 - Preparation
• Risk mapping, risk assessment, implemented controls, and risk level management.
• Creation of Playbooks, Organizational Policies, and Incident Response Plan.
• Penetration Testing, Incident Simulations, and Network segmentation.
• Internal Training and Security Awareness.
• SIEM Rules and SOC Response Simulations.
• Internal Security Audits.
CYBERPRO Israel© Copyright | Do not distribute without written permission
[Link]
b002013c6ad0
Stage 1 - Preparation
• SIEM Resource Inspection.
• Evaluation of the organizational systems integration with the SIEM Solution.
• Organizational systems mapping based on classification (IP, Location, Severity).
• Vulnerability Management.
• Threats and Potential Risks Analysis.
• Backup Configuration and Restore Simulations.
CYBERPRO Israel© Copyright | Do not distribute without written permission
[Link]
b002013c6ad0
Incident Response Plan
Lessons
Preparation Identification Containment Eradication Recovery
Learned
CYBERPRO Israel© Copyright | Do not distribute without written permission
[Link]
b002013c6ad0
How to identify a Security
Incident?
CYBERPRO Israel© Copyright | Do not distribute without written permission
[Link]
b002013c6ad0
Stage 2 - Identification
• Events can occur in many ways, and we cannot plan for every incident.
• The organization needs constant readiness and focus on a few topics:
• Main Attack Vectors
• Common Attacks
• Proactive Intelligence
• The organization may create a plan based on the most common use cases:
Brute Force External Storages/Drives
Web Application Attacks Phishing
Computers Acceptable Use IT Theft (Laptops/Phones)
Denial of Service Malwares
CYBERPRO Israel© Copyright | Do not distribute without written permission
[Link]
b002013c6ad0
Stage 2 - Identification
Severity Stages for Cyber Alerts:
Severity Description Response
Time
Critical An event with critical probability and cause heavy damage to the company its reputation. 30 Min
High An event with high probability and may cause damage to the organizational assets. 1 Hour
Medium An event which could endanger the company’s operation without low to medium impact. 4 Hours
Low An event that may affect the company’s brand. 8 Hours
CYBERPRO Israel© Copyright | Do not distribute without written permission
[Link]
b002013c6ad0
Stage 2 - Identification
• The most challenging part of an incident response is identification.
• The potential risk identification and how it should be prioritized.
• Identifying the difference between True Positive, False Positive and choosing whether an
escalation is necessary.
• In case of a true positive alert, we need to ask the following questions:
How was the event identified? What is the alert severity? And it’s risk?
What is the attack type? Was the activity identified as a suspicious behavior?
What is the attack’s scope? Were there any preliminary Indicators?
Was there suspicious cyber trend? Was the availability of an organizational system compromised?
Was there any related events? What happened before and after the attack?
When the attack began and finished? What assets are under attack and what’s the damage scope?
CYBERPRO Israel© Copyright | Do not distribute without written permission
[Link]
b002013c6ad0
Which Systems Would You
Monitor?
CYBERPRO Israel© Copyright | Do not distribute without written permission
[Link]
b002013c6ad0
Stage 2 - Identification
• Incident identification is done with the help of SIEM rules (Logic Based or Anomaly Based)
• An incident may be reported by an employee who identified suspicious behavior on a device
• Journalism coverage of a cyber-attack
• To ensure the identification of an incident we must accept logs from the following systems:
• Operation System
• Firewall
• IPS/IDS
• EDR/Anti-Virus
• DLP
• Network Components (Router/Switch)
• WAF
CYBERPRO Israel© Copyright | Do not distribute without written permission
[Link]
b002013c6ad0
Stage 2 - Identification
• Incident Analysis:
• Incident analysis would be easy without false positives (User Complaints and SIEM False positives).
• Cyber intelligence does not guarantee an attack.
• Intelligence platforms may provide invalid IOCs.
• Every activity or file should be investigated to determine its legitimacy.
• Workstation Investigation:
Registry Changes Changes in startup folder
System Services Executed Processes
Open Ports System Resources (High CPU/RAM)
Memory Dump Environment Investigation
CYBERPRO Israel© Copyright | Do not distribute without written permission
[Link]
b002013c6ad0
Stage 2 - Identification
• Incident documentation:
• It is important to document any incident which may have malicious potential and classify it as follows:
• New Event | In Progress / Mid Processing | Escalated to | Closed.
• The documentation may be used as legal evidence.
• Incident Summary:
*It is crucial to restrict access to the incident summary because it may contain sensitive data.
All the involved employees Evidence Documentation
Identified IOCs Identified suspicious activity
Workstations and Usernames Impact on the organizational systems and its stakeholders
Steps needed to terminate the incident Screenshots of evidences and alerts
CYBERPRO Israel© Copyright | Do not distribute without written permission
[Link]
b002013c6ad0
Incident Response Plan
Lessons
Preparation Identification Containment Eradication Recovery
Learned
CYBERPRO Israel© Copyright | Do not distribute without written permission
[Link]
b002013c6ad0
Stage 3 - Containment
• Containing malicious processes and terminating as required.
• At this point it is essential to establish a few ground rules:
• Who has the final say (Responsibility) for the incident response?
• Who decides to isolate a machine or shut down a server?
• Is the containment partial or complete?
• How can we achieve control over an incident?
• Blocking internet access from the organizational asset.
• Isolating machines/environments.
• Evidence collection from all sources (Logs, PCAPs, Memory Dumps, Failed Logins, etc.).
• Identify and mitigate the attack source.
• Restoration from backups and system checks.
• Termination of suspicious processes and compromised services.
CYBERPRO Israel© Copyright | Do not distribute without written permission
[Link]
b002013c6ad0
Stage 3 - Containment
• A few questions we need to ask to establish a workflow.
• What damage was caused?
• Was sensitive information stolen?
• Which evidence should be preserved?
• Which services were compromised or are unavailable?
• Were the compromised services servicing customers or employees?
• Which other services may be vulnerable?
• Digital Evidence Handling:
Logs Hostname
IP Address MAC Address
Location / Time / Dates Users and Permissions
Employees & Roles Intelligence Alerts
CYBERPRO Israel© Copyright | Do not distribute without written permission
[Link]
b002013c6ad0
Incident Response Plan
Lessons
Preparation Identification Containment Eradication Recovery
Learned
CYBERPRO Israel© Copyright | Do not distribute without written permission
[Link]
b002013c6ad0
Stage 4 - Eradication
Termination and removal of all malicious components – at this point decision-making is critical:
• Process Termination
• Malware Deletion
• Vulnerability Mitigation
• Patch Management
• Inspecting Network Communication
• Activating Disaster Recovery Policies
• Restoration from backups and creation new backups
CYBERPRO Israel© Copyright | Do not distribute without written permission
[Link]
b002013c6ad0
Incident Response Plan
Lessons
Preparation Identification Containment Eradication Recovery
Learned
CYBERPRO Israel© Copyright | Do not distribute without written permission
[Link]
b002013c6ad0
Stage 5 - Recovery
• The length of this stage changes based on the severity of the incident and may take up to a few
months or more.
• In this stage we need to check the following topics:
o Validate that all the organizational systems are working as expected.
o Inspect the needs for the development and implementation of new systems.
o Decrease future risks.
o Backup tests – Inspect integrity and Availability
o Operation System Updates & Upgrades
o Password Change & Reset across the board (Include 2FA)
o Inspect organizational security policies and disaster recovery – are they working as expected?
CYBERPRO Israel© Copyright | Do not distribute without written permission
[Link]
b002013c6ad0
Incident Response Plan
Lessons
Preparation Identification Containment Eradication Recovery
Learned
CYBERPRO Israel© Copyright | Do not distribute without written permission
[Link]
b002013c6ad0
Stage 6 – Lesson Learned & Post Investigation
• Lesson learning is the most critical stage in the response plan:
• A board meeting should be held with all participants of the incidents discussing the following:
o Incident Description
o Incident Beginning and Ending
o Was the incident response sufficient or successful?
o Were the policies satisfactory?
o Was everything adequately documented?
o How can we improve information sharing between response teams?
o Should we have done something different?
o Do we need to cooperate with external organizations?
o Would proactive intelligence better our response?
CYBERPRO Israel© Copyright | Do not distribute without written permission
[Link]
b002013c6ad0
Stage 6 – Lesson Learned & Post Investigation
• Technical Assessment for the lesson learned:
o Which vulnerabilities were exposed/exploited.
o Did the SOC issue an alert? If not, why?
o Who was the response team?
o Did the response team act appropriately and how long did it take to contain the incident?
o Did we fix the vulnerabilities? Was the fix sufficient?
o Were the risks minimized?
o How can we prevent the next attack?
o How applicable was our defense methodology?
o Was anything missing in the post-investigation?
CYBERPRO Israel© Copyright | Do not distribute without written permission
[Link]
b002013c6ad0
Stage 6 – Lesson Learned & Post Investigation
• As part of the lesson learned, creating a follow-up report for every Incident is recommended.
• The report must contain information that can be used for future investigations:
o Incident Timeline
o How long did it take to identify the incident?
o How long the incident lasted?
o How fast did the response team act?
o When was the incident reported to management?
o Estimated financial loss.
CYBERPRO Israel© Copyright | Do not distribute without written permission
[Link]
b002013c6ad0
Stage 6 – Lesson Learned & Post Investigation
• What other activities should be monitored?
o We should continue to monitor all suspicious activities regardless of incident.
o It is important to monitor all incident victims to ensure they are truly safe.
o Implement the indicators of comprises in the SIEM and other security systems.
o Create new SIEM rules based on the incident.
CYBERPRO Israel© Copyright | Do not distribute without written permission
[Link]
b002013c6ad0
The Hive Project
CYBERPRO Israel© Copyright | Do not distribute without written permission
[Link]
b002013c6ad0
What is The Hive Project?
• The Hive is a scalable, open source and free Security Incident Response
Platform designed to make life easier for SOCs, CSIRTs, CERTs and any
information security practitioner dealing with security incidents that need to
be investigated and acted upon swiftly.
CYBERPRO Israel© Copyright | Do not distribute without written permission
[Link]
b002013c6ad0
Iris – Incident Response
CYBERPRO Israel© Copyright | Do not distribute without written permission
[Link]
b002013c6ad0
What is IRIS?
• IRIS is a collaborative platform aiming to help incident responders to
share technical details during investigations.
• It's free and open-source.
CYBERPRO Israel© Copyright | Do not distribute without written permission
[Link]
b002013c6ad0
Thank You!
CYBERPRO Israel© Copyright | Do not distribute without written permission
[Link]
b002013c6ad0