Please enable JavaScript.
Coggle requires JavaScript to display documents.
π‘οΈ 1 NIST SP 800-61 Computer Security Incident Handling Guide - Coggleβ¦
π‘οΈ 1 NIST SP 800-61 Computer Security Incident Handling Guide
π§ Enterprise Linux Incident Response Framework
π Used By
1οΈβ£ SOC Operations Center
2οΈβ£ Incident Response Team
3οΈβ£ Security Operations Engineers
4οΈβ£ Government Organizations
5οΈβ£ Banking & Financial Enterprises
6οΈβ£ Cloud Security Teams
7οΈβ£ Critical Infrastructure Organizations
π¨ Incident Response Lifecycle
1οΈβ£ Preparation Phase
π― Objective
Build capability to detect, respond, investigate, and recover from security incidents
π’ Enterprise Planning
π Incident Response Policy
Define incident severity levels
Define roles and responsibilities
Define communication process
Define escalation procedures
π₯ Incident Response Team
SOC Analyst
Incident Handler
Forensic Analyst
Linux Administrator
Network Security Engineer
Threat Intelligence Analyst
Management Stakeholders
π§ Linux Security Preparation
π System Hardening
CIS Linux Benchmark
Disable unnecessary services
Remove unused packages
Secure SSH configuration
Enable firewall
Configure SELinux/AppArmor
π€ Identity Management
Strong password policy
MFA implementation
sudo privilege control
Least privilege access
User account review
π SSH Security
/etc/ssh/sshd_config
Disable root login
PermitRootLogin no
Disable password authentication
PasswordAuthentication no
Use SSH keys
Enable MFA
π§± Firewall Preparation
Ubuntu
UFW
RHEL/CentOS
firewalld
Enterprise Firewall
Network segmentation
DMZ protection
East-West traffic control
π Logging Infrastructure
Local Logs
/var/log/
Authentication Logs
Ubuntu
/var/log/auth.log
RHEL
/var/log/secure
System Logs
/var/log/syslog
Kernel Logs
dmesg
Centralized Logging
Separate Log Server
Prevent attackers deleting evidence
SIEM Integration
Elastic SIEM
Splunk
QRadar
Sentinel
β° Time Synchronization
chrony
Purpose
Maintain accurate timestamps
Importance
Correlate events across servers
Support forensic investigation
π§° Security Tools Preparation
Host Monitoring
OSSEC
Wazuh
AIDE
Vulnerability Scanner
Nessus
OpenVAS
Qualys
Rootkit Detection
rkhunter
chkrootkit
Forensics Tools
Autopsy
Sleuth Kit
Volatility
2οΈβ£ Detection & Analysis Phase
π― Objective
Identify suspicious activity
Confirm security incident
Determine impact
π Detection Sources
SIEM Alerts
Failed login attempts
Malware detection
Privilege escalation
Suspicious processes
IDS/IPS Alerts
Network attacks
Port scanning
Command and control traffic
Endpoint Detection
File Integrity Monitoring
AIDE
OSSEC
Malware Detection
ClamAV
EDR agents
π§ Linux Investigation Commands
π€ User Investigation
Check logged users
who
w
last
Check user accounts
cat /etc/passwd
cat /etc/shadow
π Authentication Investigation
Failed login attempts
grep Failed /var/log/auth.log
Successful logins
last
SSH activity
journalctl -u ssh
βοΈ Process Investigation
Running processes
ps aux
Real-time monitoring
top
htop
Suspicious processes
pstree
lsof
π Network Investigation
Active connections
ss -tulpn
Open ports
netstat -tulpn
Packet analysis
tcpdump
Wireshark
π File Investigation
Recently modified files
find / -mtime -1
SUID files
find / -perm -4000
File integrity
aide --check
π§ Incident Analysis
Determine
What happened?
When happened?
Which systems affected?
Who performed activity?
Attack method?
Business impact?
3οΈβ£ Containment Phase
π― Objective
Limit attacker activity
Prevent further damage
π‘ Short Term Containment
Network Isolation
Disconnect compromised server
Block attacker IP
Disable network interface
Firewall Blocking
iptables
firewalld
Security Groups
Account Control
Disable compromised users
usermod -L username
Reset passwords
Remove SSH keys
π΅ Long Term Containment
Build isolated investigation environment
Preserve evidence
Create forensic image
Apply temporary security controls
4οΈβ£ Eradication Phase
π― Objective
Remove attacker presence completely
π¦ Malware Removal
Identify malicious files
Remove malware
Scan system
π Root Cause Analysis
Determine
Initial access method
Vulnerability exploited
Compromised account
Malware technique
π System Cleaning
Remove unauthorized users
Remove backdoors
Remove suspicious cron jobs
Check cron
crontab -l
ls /etc/cron.*
Check services
systemctl list-unit-files
Check startup programs
systemctl list-units
π Security Improvement
Patch vulnerabilities
Update packages
apt update && apt upgrade
yum update
Harden configuration
Improve monitoring
5οΈβ£ Recovery Phase
π― Objective
Restore normal business operation safely
πΎ System Restoration
Restore backups
Rebuild compromised servers
Validate system integrity
π§ͺ Security Validation
Vulnerability scanning
Configuration review
Malware scanning
π Monitoring
Increased monitoring period
SIEM correlation rules
Alert tuning
β Return To Production
Management approval
Business validation
Documentation completed
6οΈβ£ Post-Incident Activity
π― Objective
Learn and improve security capability
π Incident Report
Executive Summary
Technical Timeline
Root Cause
Impact Analysis
Evidence Collected
Remediation Actions
π Lessons Learned
What worked?
What failed?
What should improve?
π‘ Security Improvement
Update policies
Improve detection rules
Improve logging
Update playbooks
Train employees
π Knowledge Base
Create incident documentation
Update SOC procedures
Update response checklist
π’ Enterprise Linux Incident Response Architecture
π₯ Linux Servers
Web Servers
Database Servers
Application Servers
Cloud Servers
π‘ Data Collection
Filebeat
Auditd
Sysmon Linux
OSSEC/Wazuh Agent
π§ SIEM Platform
Elasticsearch
Kibana
Logstash
Splunk
π¨βπ» SOC Team
Level 1 Analyst
Alert Monitoring
Level 2 Analyst
Investigation
Level 3 Analyst
Threat Hunting
Incident Handler
Containment & Recovery
π Incident Severity Classification
π΄ Critical
Root compromise
Data breach
Ransomware
π High
Malware infection
Privilege escalation
π‘ Medium
Suspicious login
Policy violation
π’ Low
Failed login attempts
Minor alerts
π§ͺ Practical Linux Incident Response Workflow
1οΈβ£ Receive Alert
2οΈβ£ Validate Incident
3οΈβ£ Collect Evidence
4οΈβ£ Analyze Logs
5οΈβ£ Identify Attack Path
6οΈβ£ Contain System
7οΈβ£ Remove Threat
8οΈβ£ Restore Service
9οΈβ£ Document Findings
π Improve Security Controls
π‘οΈ NIST SP 800-61
Computer Security Incident Handling Guide
1οΈβ£ Definition
A cybersecurity incident response guideline
developed to help organizations prepare for,
detect, analyze, contain, eradicate, and recover
from security incidents.
2οΈβ£ Organization
National Institute of Standards and Technology (NIST)
U.S. Government Standards Organization
Develops cybersecurity guidelines
Used worldwide by enterprises
3οΈβ£ Main Purpose
Create an enterprise incident handling program
Establish a structured response process
Improve incident detection and management
Reduce business impact of cyber attacks
Improve security after incidents
4οΈβ£ Usage
Enterprise incident response programs
Security policies and procedures
Governance and compliance activities
SOC operations
Incident response teams
Cybersecurity risk management
5οΈβ£ Audience
CISO
Security Managers
Incident Response Teams
SOC Analysts
Security Engineers
IT Administrators
6οΈβ£ Style
Structured guideline
Formal methodology
Policy-driven approach
Enterprise-focused framework
7οΈβ£ Focus
Complete incident management lifecycle
Incident preparation
Detection and analysis
Containment
Eradication
Recovery
Post-incident improvement
8οΈβ£ Incident Response Lifecycle
Preparation
Create incident response plan
Build response team
Deploy security tools
Enable logging and monitoring
Establish communication process
Detection & Analysis
Identify security events
Analyze alerts
Validate incidents
Determine impact
Collect evidence
Containment
Limit attacker activity
Isolate affected systems
Block malicious access
Prevent further damage
Eradication
Remove malware
Remove persistence mechanisms
Patch vulnerabilities
Secure compromised accounts
Recovery
Restore systems
Validate security
Monitor for recurrence
Return to normal operation
Post-Incident Activity
Create incident report
Perform root cause analysis
Document lessons learned
Improve controls
Update response procedures