Please enable JavaScript.
Coggle requires JavaScript to display documents.
2 SANS Incident Response Framework Very popular in SOC environments. -โฆ
2 SANS Incident Response Framework
Very popular in SOC environments.
๐ก๏ธ SANS Incident Response Framework
๐ข Enterprise Linux SOC Incident Response Lifecycle
1๏ธโฃ Preparation Phase
๐ฏ Objective
Build capability before security incidents occur
Reduce response time
Improve detection and recovery
๐๏ธ Enterprise Preparation Activities
๐ฅ๏ธ Linux Infrastructure Readiness
Linux server inventory
Hostname
IP address
Operating system version
Installed applications
Owner information
Asset classification
Critical servers
Database servers
Web servers
Authentication servers
Production systems
๐ Security Configuration
Enable secure authentication
SSH hardening
MFA implementation
Disable root SSH login
User and privilege management
sudo configuration
Least privilege access
Role-based access control
Firewall configuration
firewalld
iptables
nftables
๐ Logging and Monitoring
Linux Logs
/var/log/auth.log
/var/log/secure
/var/log/syslog
/var/log/messages
Centralized Logging
Separate log server
Prevent attacker log modification
Log retention policy
Tools
SIEM
Elastic SIEM
Splunk
QRadar
Log collectors
Filebeat
Fluent Bit
Syslog-ng
๐ ๏ธ Incident Response Tools Preparation
Forensics Tools
Autopsy
Sleuth Kit
Volatility
Malware Analysis
YARA
ClamAV
System Investigation
lsof
ps
netstat
ss
strace
Integrity Monitoring
AIDE
OSSEC
Wazuh
2๏ธโฃ Identification Phase
๐ฏ Objective
Detect and confirm security incidents
๐จ Alert Sources
SIEM Alerts
Failed SSH login
Malware detection
Privilege escalation
Suspicious process
Security Tools
IDS/IPS
EDR
Vulnerability Scanner
User Reports
Account compromise
System slowdown
Unauthorized changes
๐ Incident Validation
Confirm Alert
False positive check
Event correlation
Log verification
Determine Incident Type
๐ Credential Attack
SSH brute force
Password spraying
Stolen credentials
๐ฆ Malware Infection
Unknown processes
Suspicious files
Rootkit detection
๐ค Privilege Escalation
Unauthorized sudo access
SUID abuse
Kernel exploitation
๐ฅ Evidence Collection
System Information
Host details
hostname
uptime
kernel version
Users
cat /etc/passwd
last
who
w
Process Investigation
Running processes
ps aux
Open files
lsof
Network connections
ss -tulpn
netstat -antp
3๏ธโฃ Containment Phase
๐ฏ Objective
Stop attacker activity and limit damage
๐ง Short-Term Containment
Network Isolation
Block attacker IP
firewall rules
security groups
Disconnect compromised host
Account Control
Disable compromised user
usermod -L username
Reset passwords
Revoke sessions
๐ Long-Term Containment
Security Hardening
Patch vulnerabilities
Update passwords
Enable MFA
Improve firewall rules
๐ Evidence Preservation
Create forensic copy
Preserve logs
Capture memory
RAM acquisition
Document timeline
4๏ธโฃ Eradication Phase
๐ฏ Objective
Remove attacker presence completely
๐ Root Cause Analysis
Identify entry point
Vulnerability exploited
Weak password
Phishing
Misconfiguration
๐งน Remove Threat
Malware Removal
Delete malicious files
Remove backdoors
Kill malicious processes
Persistence Removal
Check cron jobs
crontab -l
Check startup services
systemctl list-unit-files
Check SSH keys
~/.ssh/authorized_keys
Check users
/etc/passwd
๐ System Hardening
Update packages
apt update
apt upgrade
Fix permissions
chmod
chown
Security policies
SELinux
AppArmor
5๏ธโฃ Recovery Phase
๐ฏ Objective
Restore normal business operation safely
๐ System Restoration
Restore from backup
Rebuild compromised servers
Validate system integrity
๐งช Security Validation
Vulnerability scanning
Nessus
OpenVAS
Qualys
Configuration Review
CIS Benchmark
NIST Controls
๐ Monitoring After Recovery
Increased logging
SIEM monitoring
Watch suspicious activity
User activity monitoring
6๏ธโฃ Lessons Learned Phase
๐ฏ Objective
Improve future incident response
๐ Incident Report
Executive Summary
Timeline
Impact Assessment
Root Cause
Actions Taken
๐ Technical Review
What happened?
How attacker entered?
Which controls failed?
What evidence was collected?
๐ ๏ธ Improvement Actions
Update security policies
Improve monitoring rules
Add detection signatures
Patch vulnerabilities
๐ Knowledge Sharing
SOC training
Playbook updates
Security awareness training
๐ฅ๏ธ Enterprise Linux SSH Brute Force Example
๐จ Detection
SIEM Alert
Multiple failed SSH logins
Same source IP
Multiple usernames
1๏ธโฃ Identification
Collect Evidence
Authentication Logs
Ubuntu
/var/log/auth.log
RHEL
/var/log/secure
Commands
last
lastb
journalctl -u ssh
grep "Failed password" /var/log/auth.log
2๏ธโฃ Containment
Block Attacker
Firewall
ufw deny attacker_IP
firewall-cmd --add-rich-rule
Disable Account
passwd -l username
Terminate Sessions
pkill -u username
3๏ธโฃ Eradication
Remove Persistence
Check SSH keys
~/.ssh/authorized_keys
Check Users
/etc/passwd
Check Cron
crontab -l
Patch System
apt update
apt upgrade
4๏ธโฃ Recovery
Restore Service
Restart SSH
systemctl restart ssh
Monitor
SIEM dashboard
Authentication logs
5๏ธโฃ Lessons Learned
Improve Controls
Enable MFA
Disable password login
Use SSH keys
Implement fail2ban
Update SOC playbook
๐ข Enterprise SOC Integration
๐จโ๐ป SOC Analyst Level 1
Alert Monitoring
Initial Investigation
Evidence Collection
๐จโ๐ป SOC Analyst Level 2
Threat Hunting
Root Cause Analysis
Containment
๐จโ๐ป Incident Responder
Digital Forensics
Malware Analysis
Recovery Planning
๐จโ๐ผ Security Manager
Risk Assessment
Compliance Reporting
Lessons Learned
๐ Framework Mapping
SANS IR Framework
Preparation
NIST Preparation
Identification
NIST Detection & Analysis
Containment
NIST Containment
Eradication
NIST Eradication
Recovery
NIST Recovery
Lessons Learned
NIST Post-Incident Activity
๐ฏ Enterprise Goal
Detect Faster
Contain Quickly
Remove Threat Completely
Restore Secure Operations
Prevent Repeat Incidents
๐ก๏ธ SANS Incident Response Framework
๐ Full Name
SANS Incident Response Process
๐ข Organization
SANS Institute
๐ฏ Main Purpose
Provide practical steps for incident responders
Guide security teams during real attacks
Provide a structured response workflow
Help reduce incident impact
โ๏ธ Usage
SOC Operations
Daily Security Response
Incident Investigation
Threat Detection
Malware Investigation
Security Incident Handling
๐ฅ Audience
SOC Analysts
Incident Responders
Security Engineers
Threat Hunters
Digital Forensics Analysts
๐ Style
Hands-on
Operational Workflow
Practical Approach
Step-by-Step Process
Action-Oriented
๐ Focus
Fast Investigation
Quick Detection
Incident Analysis
Containment
Eradication
Recovery
Lessons Learned