Cyberstudy
PDF p.303 In progress

Eradication and Recovery

Open PDF at p.303 10 flashcards

Summary

PDF p.303

After containment, eradication involves removing intrusion tools and unauthorized changes, while recovery restores system capabilities and services. This ensures systems are reconfigured to their pre-incident state and protected against future attacks.

In plain words

Supplementary — not from your PDF

Eradication removes the attacker's tools and changes, either by cleaning systems or by restoring from known-good backups or images. Update baseline templates so the same weakness doesn't return, re-audit security controls, and notify affected parties (for example, telling customers to reset passwords). Recovery brings systems back into normal business use and monitors the original attack path for any repeat.

Detailed explanation

PDF p.303

Eradication Steps

  • Reconstitution of Affected Systems
    • Methods: Remove malicious files/tools or restore systems from secure backups/images.
    • Baseline Templates: Ensure templates are updated to prevent recurrence of the incident.
  • Reaudit Security Controls
    • Purpose: Ensure controls are not vulnerable to the same or new attacks.
    • Awareness: Be prepared for potential follow-up attacks in targeted incidents.
  • Notification
    • Affected Parties: Inform and provide remediation steps, such as advising customers to change compromised passwords.

Recovery Steps

  • Restoration of Capabilities
    • Reconfiguration: Fully reconfigure hosts to their pre-incident business workflow.
    • Monitoring: Ensure the system cannot be compromised through the same attack vector or closely monitor the vector for future attacks.

Important terms

taken from the text above
Baseline Templates
Ensure templates are updated to prevent recurrence of the incident.
Awareness
Be prepared for potential follow-up attacks in targeted incidents.
Affected Parties
Inform and provide remediation steps, such as advising customers to change compromised passwords.
Reconfiguration
Fully reconfigure hosts to their pre-incident business workflow.

Examples & real-world scenarios

Supplementary — not from your PDF
  • Reimaging a compromised laptop from a gold image.
  • Patching the vulnerability that was exploited before bringing the server back.
  • Extra monitoring on a restored web server for 30 days.

Scenario

After ransomware, a server is restored from backup, but the RDP weakness the attacker used is still open. Eradication must include closing that path, or recovery will fail.

Common mistakes

Supplementary — not from your PDF
  • Restoring backups that may already contain the attacker's changes.
  • Returning systems to service without extra monitoring.

Practical skills

Supplementary — not from your PDF
  • Write an eradication and recovery checklist.

What I should remember

Key Points PDF p.303
  • Eradication
    • Reconstitution: Remove malicious files or restore from backups.
    • Baseline Templates: Update to prevent recurrence.
    • Reaudit Controls: Ensure security controls are robust.
    • Notification: Inform affected parties and provide remediation steps.
  • Recovery
    • Restoration: Reconfigure systems to pre-incident state.
    • Monitoring: Protect against future attacks.