Showing posts with label CSIRT. Show all posts
Showing posts with label CSIRT. Show all posts

Monday, May 15, 2017

Ransomware & Incident Response: Thoughts from WannaCry, WannaCry2, & WannaCrypt0r

Lots of content has been created for detecting & dealing with ransomware; however, these past few days have seen a flurry of different attacks & thus require some specific after-action reports (AAR).

So, here are some observations / thoughts / notes:


  • Many orgs do not have the budget to ward off ransomware, including: 
    • Advanced threat protection (ATP) via: EDR, UBA / UEBA, UTM / NGFW / NGIPS / NGIDS
    • Virtualization to segment legacy tech: SDN, SDS, hyperconvergence
    • SIEM & TI
  • SETA & CSIRT awareness notifications were slow & ineffective
  • Close the patching gap....no more excuses
  • We'll see this level of pandemic / infestation again...this is just a start.
So, folks will see this level of attack again & its up to them to be proactive & respond accordingly.

Saturday, April 22, 2017

OODA Framework for TI / DFIR / CSIR Process Engineering

THE OODA Loop (https://en.wikipedia.org/wiki/OODA_loop) can be used to develop workflows for TI / DFIR / CSIR, including leveraging TIMP implementations, like MineMeld (https://www.paloaltonetworks.com/products/secure-the-network/subscriptions/minemeld).

Monday, July 4, 2016

Don't Forget to Plan

In the midst of the Brexit mess, we are reminded to plan before we take action.

Case in point, perform due diligence regarding information security before a merger or acquisition.  Likewise, have access controls in place before a divestiture.  Finally, test an incident response / disaster recovery plan before either really happens.

Regardless of one's position on Iraq 2003 or Brexit 2016, let's learn from one's inability to plan.