Playbooks

From
Bret Jordan <>
Date
2019-09-26T14:40:00+00:00
ID
Thread
Playbooks
Frans,

  Are you looking for examples of what exists in the SoC today?  If you search for "security playbooks  on Google the first 2 or 3 non sponsored links have some visual examples.  In slide ware, when I talk about this, I often give the follow examples
  as it is something that most people can easily understand:

Security Operations Center

Open ticket with priority level 2

Call level one network support

If they do not respond within 10 minutes

Escalate to level 2, then level 3, then management

Network Support

Quarantine system to sandbox VLAN

Security Operations Center

Call level level one desktop support

If they do not respond within 30 minutes

Escalate to level 2, then level 3, then management

Desktop Support

Delete run at start reg keys and triggers

Reboot into SafeMode

Kill process sysmg.exe then winsrvx.exe then xnc.exe

Delete temp files

Delete compromised files defined in KB article 311

Delete other registry keys defined in KB article 312

Reboot system in to safe mode

Verify processes do not restart after cleanup

If this does not work, escalate

Patch AV system and run updated AV scan

Patch OS

Run additional on-demand special AV scanners

Reboot system to normal mode

Update ticket

Network Support

Monitor traffic from system for 90 minutes

If no abnormal behavior is detected move system out of sandbox VLAN in to a restricted watch VLAN for 24 hours

If no user issues or abnormal behavior is detected move system to production VLAN

Update and close ticket

  Bret

  On Sep 26, 2019, at 1:34 AM, Frans Schippers < 
> wrote:

  Dear members

 Can anyone share some playbooks with me?

 Frans Schippers
 Cyber Security
 Lecturer / Researcher

 Amsterdam Universe of Applied Science
 HBO-ICT
 Wibautstraat 2-4
 1091 GM Amsterdam

 PGP: 12D1 D930 488C 22B7 6AFF  BFF7 218C 865E D6E0 6B48