Soru

Zorluk: ZorEndpoint Detection and Response (EDR)

A Security Operations Center (SOC) analyst receives a high-severity Endpoint Detection and Response (EDR) alert indicating an active living-off-the-land attack where a compromised workstation is attempting lateral movement via WMI and fileless memory injection. Arrange the following incident response containment and forensic actions in the correct sequential order from first step to last step.

  1. 1Initiate soft network isolation on the affected endpoint via the EDR management console to block lateral movement while maintaining agent communication.
  2. 2Collect a volatile RAM image and active process telemetry dump remotely through the EDR agent.
  3. 3Terminate the malicious process tree and kill injected code threads on the target host.
  4. 4Publish the extracted file hashes and behavioral Indicators of Compromise (IOCs) as a global ban rule across all enterprise EDR agents.

Cevap

The correct sequence places host network isolation first, followed by volatile memory collection, active process tree termination, and finally fleet-wide IOC ban rule enforcement.
In security incident response workflows, immediate containment of lateral movement is prioritized first by applying EDR network host isolation. Next, adherence to the order of volatility dictates collecting RAM and process dumps prior to killing active processes. Once volatile evidence is safely captured, active malicious process trees are terminated to stop local adversary activity. Finally, extracted IOCs are distributed enterprise-wide as EDR ban rules to protect remaining fleet endpoints.

Adım Adım Çözüm

1
Isolate host using EDR network containment tools.
Network traffic to and from the host is restricted to the EDR cloud sensor, immediately stopping lateral movement.
Containment is the immediate priority during active lateral movement attacks to limit blast radius.
2
Trigger remote volatile RAM and process dump collection.
Volatile memory evidence is stored safely before process alteration.
Order of volatility requires capturing RAM and volatile evidence before altering system memory state.
3
Kill malicious processes and injected execution threads.
Malicious code execution on the endpoint ceases completely.
Terminating processes stops ongoing attacker activity without losing evidence previously captured in Step 2.
4
Distribute IOC ban rules across all enterprise EDR endpoints.
Enterprise-wide protection is established against the identified attack signature.
Remediation and preventive policy enforcement ensure fleet-wide protection after containment.

Anahtar Kavram

EDR Incident Containment Sequence & Volatility Management
Bu soruyu puanla