Eradication and Recovery
Summary
PDF p.303After containment, eradication involves removing intrusion tools and unauthorized changes, while recovery restores system capabilities and services. This ensures systems are reconfigured to their pre-incident state and protected against future attacks.
In plain words
Supplementary — not from your PDFEradication removes the attacker's tools and changes, either by cleaning systems or by restoring from known-good backups or images. Update baseline templates so the same weakness doesn't return, re-audit security controls, and notify affected parties (for example, telling customers to reset passwords). Recovery brings systems back into normal business use and monitors the original attack path for any repeat.
Detailed explanation
PDF p.303Eradication Steps
-
Reconstitution of Affected Systems
- Methods: Remove malicious files/tools or restore systems from secure backups/images.
- Baseline Templates: Ensure templates are updated to prevent recurrence of the incident.
-
Reaudit Security Controls
- Purpose: Ensure controls are not vulnerable to the same or new attacks.
- Awareness: Be prepared for potential follow-up attacks in targeted incidents.
-
Notification
- Affected Parties: Inform and provide remediation steps, such as advising customers to change compromised passwords.
Recovery Steps
-
Restoration of Capabilities
- Reconfiguration: Fully reconfigure hosts to their pre-incident business workflow.
- Monitoring: Ensure the system cannot be compromised through the same attack vector or closely monitor the vector for future attacks.
Important terms
taken from the text above- Baseline Templates
- Ensure templates are updated to prevent recurrence of the incident.
- Awareness
- Be prepared for potential follow-up attacks in targeted incidents.
- Affected Parties
- Inform and provide remediation steps, such as advising customers to change compromised passwords.
- Reconfiguration
- Fully reconfigure hosts to their pre-incident business workflow.
Examples & real-world scenarios
Supplementary — not from your PDF- Reimaging a compromised laptop from a gold image.
- Patching the vulnerability that was exploited before bringing the server back.
- Extra monitoring on a restored web server for 30 days.
Scenario
After ransomware, a server is restored from backup, but the RDP weakness the attacker used is still open. Eradication must include closing that path, or recovery will fail.
Common mistakes
Supplementary — not from your PDF- Restoring backups that may already contain the attacker's changes.
- Returning systems to service without extra monitoring.
Practical skills
Supplementary — not from your PDF- Write an eradication and recovery checklist.
What I should remember
Key Points PDF p.303-
Eradication
- Reconstitution: Remove malicious files or restore from backups.
- Baseline Templates: Update to prevent recurrence.
- Reaudit Controls: Ensure security controls are robust.
- Notification: Inform affected parties and provide remediation steps.
-
Recovery
- Restoration: Reconfigure systems to pre-incident state.
- Monitoring: Protect against future attacks.