Knowledgebase

Investigating a Security Incident Print

  • 0

Establishing what an attacker did.

WHAT TO ESTABLISH

How they got in What they reached What they took or changed Whether they still have access When it began

WHY THE LAST QUESTION MATTERS MOST

The starting point determines the scope of everything.

WHAT TO AVOID ASSUMING

That the incident began when you noticed it.

WHY

Compromises are typically present long before discovery.

WHAT TO DO

Work backwards from the earliest evidence.

WHAT TO EXAMINE

Authentication records for unusual access Accounts created or modified Software installed Scheduled tasks created Network connections to unfamiliar destinations Files added or changed Configuration changes

WHY SCHEDULED TASKS AND ACCOUNTS

They are how access is retained after the original route is closed.

WHAT TO ESTABLISH BEFORE CONCLUDING

That every route back in has been found.

WHY

Removing the obvious one and leaving another means the compromise continues.

WHAT TO ASSESS ABOUT DATA

What was accessible to the compromised account Whether large transfers occurred Whether anything was staged for extraction

WHY STAGED DATA

Collected files awaiting transfer indicate intent and scope.

WHAT TO ESTABLISH ABOUT OTHER SYSTEMS

Whether the compromise spread.

HOW

Look for the same indicators elsewhere.

WHAT TO ASSUME ABOUT CREDENTIALS

That anything accessible from the compromised system is compromised.

WHAT TO DO

Change them.

WHAT TO RECORD

The timeline, with evidence for each point.


Was this answer helpful?
Back

Are you happy with your experience? Leave us a review on Trustpilot.


Trustpilot