Soru

Zorluk: ZorIncident Response Process and Playbooks

A security operations center (SOC) analyst confirms an active Golden Ticket attack originating from a compromised Active Directory Domain Controller within an enterprise network. Arrange the following incident response procedures in the correct chronological order according to standard NIST incident response lifecycle guidelines, starting with the earliest step.

  1. 1Isolate the compromised Domain Controller from the broader network and revoke all active administrative sessions.
  2. 2Reset the krbtgt account password twice consecutively and purge all persistent malware artifacts from the system.
  3. 3Restore directory state from verified offline backups, re-engage domain authentication, and monitor Kerberos ticket requests.
  4. 4Conduct an after-action review to document breach metrics, update Tier-0 incident playbooks, and mandate hardware token MFA.

Cevap

The correct order follows the standard NIST SP 800-61 r2 Incident Response Lifecycle: Containment (network isolation and session revocation) → Eradication (double krbtgt password reset and malware removal) → Recovery (backup restoration, service re-engagement, and monitoring) → Post-Incident Activity (after-action review and playbook updates).
According to standard NIST incident response guidelines (SP 800-61 r2), containment must always precede eradication to restrict adversary movement. Once isolated, eradication eliminates the root cause and attacker access methods (such as invalidating Kerberos TGTs via a double krbtgt reset). Recovery follows to safely restore verified services into production under heightened monitoring, and post-incident activities take place last to document lessons learned and refine security controls.

Adım Adım Çözüm

1
Identify the initial Containment action.
Network isolation of the Domain Controller and revocation of administrative sessions prevents the attacker from propagating across the enterprise.
Containment must occur first upon confirming an intrusion to limit the scope of compromise.
2
Identify the Eradication action.
Resetting the krbtgt account password twice invalidates all existing Ticket Granting Tickets (including forged Golden Tickets), and removing backdoors eliminates root access vectors.
Eradication neutralizes the threat completely so that systems can be safely brought back online.
3
Identify the Recovery action.
Restoring directory services from clean backups, resuming domain authentication, and closely monitoring ticket traffic confirms operational integrity.
Recovery restores impacted infrastructure to normal operational status in a controlled, monitored environment.
4
Identify the Post-Incident Activity action.
Performing an after-action debriefing, updating incident playbooks, and implementing stronger access controls enhances enterprise resilience.
Lessons learned activities document the incident response performance and refine operational defenses against future attacks.

Anahtar Kavram

NIST Incident Response Lifecycle (Containment, Eradication, Recovery, Post-Incident Activity)
Bu soruyu puanla