CySA+ · Domain 3
Incident Response and Management
About 24% of the exam
The lifecycle
- Preparation
- Detection and analysis
- Containment
- Eradication
- Recovery
- Post-incident activity
- Preparation is where the value sits
- Analysis scopes before anything is touched
- Containment buys time for eradication
- Recovery restores and then watches
- Lessons learned assigns owners and dates
Containment, eradication and recovery are often examined as one phase, but the order inside them never changes
Attack frameworks
- Cyber kill chain
- seven stages, recon to objectives
- Diamond model
- adversary, capability, infrastructure, victim
- MITRE ATT&CK
- tactics, techniques and real procedures
- Pyramid of pain
- behavior hurts attackers most
- OSSTMM
- methodology for security testing
- OWASP testing guide
- web application test coverage
Detection and triage
- Validate before declaring an incident
- Classify by impact and urgency
- Record the first observed timestamp
- Identify patient zero and entry point
- Preserve evidence while you triage
- Decide whether it is a breach
Scoping
- Blast radius
- which hosts and accounts are touched
- Data impact
- what was read, copied or changed
- Downtime
- services affected and for how long
- Economic impact
- cost of outage and recovery
- Recovery time
- how long restoration will take
- Detection source
- alert, user or third party
- Attribution
- interesting, rarely the priority
Containment choices
Short term
- Isolate the host but keep it running
- Block the command and control address
- Disable the compromised account
- Sinkhole the malicious domain
- Capture memory before disconnecting
Long term
- Rebuild from a known good image
- Patch the exploited vulnerability
- Rotate credentials, keys and tokens
- Harden and re-segment before return
Cloud and container
- Snapshot volumes before terminating anything
- Containers vanish, so collect immediately
- Tighten the security group rather than deleting
- Preserve the provider audit logs
Isolation keeps the evidence and stops the spread; powering off destroys memory and tells the attacker you noticed
Digital forensics
Acquisition
- Volatility order: registers, memory, disk
- Capture memory before any shutdown
- Image bit for bit behind a write blocker
- Hash before and after acquisition
- Photograph and label the scene
Analysis
- Build a timeline from file timestamps
- Volatility reveals injection and hidden processes
- Carve deleted files from unallocated space
- Correlate host evidence with network evidence
Integrity and law
- Chain of custody signed at every handover
- Legal hold suspends deletion schedules
- Counsel direction can create privilege
- Report facts apart from opinion
Eradication checklist
- Remove malware, tooling and web shells
- Delete attacker created accounts
- Clear rogue scheduled tasks and services
- Check run keys and startup folders
- Firmware persistence survives a reinstall
- Rebuild rather than clean when unsure
Recovery
- Restore from backups predating the compromise
- Verify integrity before returning to service
- Return in stages and monitor closely
- Keep detections tuned for return visits
- Business owners confirm the restoration
- Record when normal operations resumed
Persistence to hunt for
- Scheduled task
- runs the payload on a timer
- Run key
- launches at user logon
- Service
- an auto starting malicious service
- WMI subscription
- fires on a system event
- Web shell
- a script in a web directory
- New account
- added quietly to administrators
- Forged ticket
- Kerberos authentication minted offline
- SSH key
- attacker key in authorized keys
Who gets told, and when
- Incident commander
- decides and owns the timeline
- Legal counsel
- assesses notification duty first
- Communications
- one voice to customers and press
- Regulator
- clock starts at awareness
- Law enforcement
- per policy and severity
- Out-of-band channel
- assume the network is watched
- Third parties
- vendors and affected partners
Post-incident activity
- Find root cause, not proximate cause
- Review while the memories are fresh
- Assign owners and deadlines to actions
- Track recommendations through to completion
- Feed findings into detection content
- Update the playbooks and the plan
Preparation
- The plan names roles and escalation
- Playbooks for the likely scenarios
- Tabletop exercises include business stakeholders
- Tools and forensic media ready
- Contact lists tested and current
- Retainer agreed before you need it
- Backups immutable and restore tested
Know the order
- Lifecycle
- prepare, detect, contain, eradicate, recover
- Then
- post-incident review and updates
- Volatility
- registers, memory, network state, disk
- Containment
- short term before long term
- Evidence
- acquire, hash, analyze, report
- Notification
- counsel first, then regulators
Key numbers
- GDPR notification
- 72 hours from awareness
- Kill chain
- seven stages in order
- Lifecycle phases
- four grouped, six taught
- Hashing
- before and after acquisition
- Tabletop cadence
- at least once a year
Reference strip: frameworks, evidence, actions, people
Frameworks
- Kill chain, diamond model, ATT&CK
- Pyramid of pain for indicator value
- OSSTMM and OWASP testing guide
- Playbooks mapped to techniques
Evidence
- Order of volatility and memory capture
- Write blockers and forensic imaging
- Hashing, chain of custody, legal hold
- Timelines and artifact correlation
Containment
- Isolate, block, disable, sinkhole
- Segmentation and access revocation
- Snapshots before cloud termination
- Credential and key rotation
Recovery
- Rebuild from known good images
- Restore from clean backups
- Staged return with monitoring
- Business acceptance of service
People
- Incident commander and scribe
- Legal, privacy and communications
- Regulators, customers, law enforcement
- Out-of-band communication channels
Quick exam traps
- Trap: Powering the host off is the safest containment
- Trap: Reimaging first and investigating later saves time
- Trap: Attribution has to be settled before containment
- Trap: Restoring the newest backup is always correct
- Trap: A cloud instance can be terminated and studied later
- Trap: Root cause analysis is the same as blaming an operator
- Trap: Notification timelines start when the fix is finished
- Trap: A tabletop exercise only concerns the security team
cybercertprep.com · original revision sheet written from the public body of knowledge