The Inner Circle

DHS JOINT CYBERSECURITY ADVISORY September 1, 2020 Technical Approaches to Uncovering and Remediating Malicious Activity

  • 1.  DHS JOINT CYBERSECURITY ADVISORY September 1, 2020 Technical Approaches to Uncovering and Remediating Malicious Activity

    Posted 19 days ago
      |   view attached
    Hi All,

    The Department of Homeland Security issued a JOINT CYBERSECURITY ADVISORY September 1, 2020, Technical Approaches to Uncovering and Remediating Malicious Activity

    Summary
    This joint advisory is the result of a collaborative research effort by the cybersecurity authorities of five nations: Australia, Canada, New Zealand, the United Kingdom, and the United States. It highlights technical approaches to uncovering malicious activity and includes mitigation steps according to best practices. The purpose of this report is to enhance incident response among partners and network administrators along with serving as a playbook for incident investigation.

    Key Takeaways

    When addressing potential incidents and applying best practice incident response procedures:

    • First, collect and remove for further analysis:
      • Relevant artifacts,
      • Logs, and
      • Data.
    • Next, implement mitigation steps that avoid tipping off the adversary that their presence in the network has been discovered.
    • Finally, consider soliciting incident response support from a third-party IT security organization to:
      • Provide subject matter expertise and technical support to the incident response,
      • Ensure that the actor is eradicated from the network, and
      • Avoid residual issues that could result in follow-up compromises once the incident is closed.


    ------------------------------
    Michael Roza CPA, CISA, CIA
    ------------------------------