How to Build and Apply an Incident Response Plan

68 views
β€’
August 22, 2022
by
RSAC Cybersecurity
YouTube video player
How to Build and Apply an Incident Response Plan

TL;DR

An effective incident response plan must preserve evidence, identify the original entry point, and remove the underlying weakness before systems are restored. Organizations should also limit local administrator access, monitor remote connections, prepare response procedures in advance, and teach employees to recognize phishing through security lessons that connect workplace behavior with personal consequences.

Transcript

Thank you. So, uh, welcome everyone again. Uh, my name is Mike Jankowski Lorek. I'm Director of Consulting and Cybersecurity Expert, uh, working with, uh, and for CQURE. Um, I'm doing lots of penetration testing, but as well, a lot of other consulting work, as well the incident response. And, uh, this time I will be talking about, uh, improving and... Read More

Key Insights

  • Incident recovery is incomplete until responders determine how the attacker entered, what actions occurred, and which weakness enabled the compromise. Simply restoring backups can return operations temporarily while leaving the original access route available for another attack.
  • Evidence preservation is essential during incident response because memory dumps, disk copies, virtual machine states, network flows, and captured traffic can reveal the attack path. Recovering systems before gathering these materials may deprive investigators of the information needed for a reliable analysis.
  • An exposed legacy web server can compromise an entire environment when its service runs with domain administrator privileges. A weakness in that server can therefore provide an attacker with excessive access, making both outdated systems and overprivileged service accounts important investigative targets.
  • Email is a practical delivery channel for malicious links and attachments because opening shared documents and following links are normal parts of daily work. Attackers can imitate familiar messages and interfaces to persuade users to enable content or open protected-looking files.
  • Multi-factor authentication does not eliminate phishing risk because the demonstrated approach can capture passwords, obtain authentication confirmation, and acquire a refresh token. Organizations must therefore prepare for phishing that targets both user credentials and the mechanisms surrounding authenticated sessions.
  • Privilege escalation becomes easier when ordinary users have local administrator access or when software configurations permit malicious DLL placement. Attackers can also use scripts that identify escalation opportunities and provide instructions for exploiting them, reducing the expertise required to expand control.
  • Built-in administration tools can be abused during an attack because utilities such as CertUtil and PowerShell can decode, download, or execute malicious content. Responders should not assume that activity is harmless merely because it uses software already included with the operating system.
  • Security awareness is more engaging when lessons connect workplace behavior to employees' personal cybersecurity. Employees may pay closer attention when unsafe actions are explained through consequences for their own computers, expenses, and recovery responsibilities, then apply the same caution within the organization.

Install to Summarize YouTube Videos and Get Transcripts

Explore YouTube Video Summarizer or Get YouTube Transcript Extractor

Questions & Answers

Q: How should an organization respond after discovering a cyberattack?

The organization should activate a prepared incident response process, preserve available evidence, gather network traffic and system information, and investigate how the attacker gained access. Recovery should not begin as an isolated restoration exercise. Responders must identify and close the original entry point so restored systems are not exposed to the same compromise again.

Q: Why is restoring backups alone insufficient after a ransomware incident?

Restoring backups may bring systems back into operation, but it does not explain how the attacker entered or whether the weakness remains available. The transcript describes an organization that restored its environment without preserving evidence and was compromised again through the same route. Effective recovery must include investigation, evidence collection, and remediation of the original vulnerability.

Q: What evidence should responders preserve during an incident?

Responders should preserve memory dumps, copies of hard disks, saved states of virtual machines, network flows, captured network traffic, and other information gathered during recovery. These materials help investigators reconstruct attacker activity and locate the initial access path. If systems are restored or altered first, valuable evidence may disappear before analysts can examine it.

Q: How can a legacy web server create organization-wide risk?

A legacy web server can become an entry point when it remains exposed and contains an exploitable weakness. The risk becomes much greater if its service runs under a domain administrator account. In the incident described, access through such a server allowed an attacker to reach the broader environment because the service possessed excessive privileges.

Q: How does a phishing attachment lead to remote computer control?

A user opens an attachment designed to execute malicious instructions, after which the client computer initiates a connection to the attacker's system. The attacker then receives a remote session and can operate within the user's security context. Because the compromised computer starts the connection, the attacker can control it from another location without being physically near the organization.

Q: How do attackers escalate from a standard user to system privileges?

Attackers can download and run privilege-escalation scripts that inspect a computer for exploitable configurations. The demonstration identifies a location where a DLL can be placed, downloads a malicious payload under the expected name, and relies on a restart to load it. The resulting session runs with system privileges, giving the attacker extensive control over the computer.

Q: Why should employees avoid unnecessary local administrator rights?

Local administrator rights make an attacker's work easier after a user account or computer is compromised. With elevated access, the attacker can perform more powerful actions, obtain credentials, inspect saved browser passwords, and continue attacking the environment. Removing unnecessary administrator privileges limits what a compromised standard user session can immediately accomplish and creates another barrier to escalation.

Q: How can security awareness training make phishing lessons more relevant?

Security awareness training can frame cybersecurity through employees' personal computers and personal consequences. Workers may care more when a compromise could force them to pay for repairs or recover their own encrypted device, rather than simply calling corporate support. That personal perspective can encourage safer behavior that employees also carry into the workplace.

Summary & Key Takeaways

  • Incident response fails when organizations treat recovery as the only objective. Restoring systems without collecting memory dumps, disk copies, virtual machine states, network traffic, and other evidence can erase the information needed to understand an attack. If the original access path remains open, attackers can compromise the environment again.

  • A demonstrated phishing attack begins when a user opens a malicious attachment. The compromised computer initiates a remote connection to the attacker, allowing control from any location. Readily available scripts and built-in Windows utilities can then help the attacker download payloads, discover escalation opportunities, and execute malicious code.

  • Preparation combines technical controls, documented response procedures, evidence preservation, and employee education. Users should not receive local administrator privileges without a clear need. Security awareness training may gain more attention when it connects phishing and unsafe computer behavior to employees' personal devices, costs, and responsibility rather than discussing only corporate infrastructure.


Read in Other Languages (beta)

Share This Summary πŸ“š

Explore More Summaries from RSAC Cybersecurity πŸ“š