1
1

00:00:00,720  -->  00:00:04,620
<v ->Documenting procedures, one of the first steps</v>
2

2

00:00:04,620  -->  00:00:05,937
inside of your preparation phase
3

3

00:00:05,937  -->  00:00:09,090
is going to be to document procedures.
4

4

00:00:09,090  -->  00:00:10,967
Now again, let's review the preparation phase
5

5

00:00:10,967  -->  00:00:12,540
and what it does.
6

6

00:00:12,540  -->  00:00:14,010
When we're in the preparation phase,
7

7

00:00:14,010  -->  00:00:16,170
we are trying to make the system resilient to attack
8

8

00:00:16,170  -->  00:00:19,320
by hardening our systems, writing policies and procedures,
9

9

00:00:19,320  -->  00:00:22,020
and setting up confidential lines of communication.
10

10

00:00:22,020  -->  00:00:23,970
So writing these policies and procedures
11

11

00:00:23,970  -->  00:00:26,730
and documenting them is very important.
12

12

00:00:26,730  -->  00:00:28,560
By preparing for an instant response,
13

13

00:00:28,560  -->  00:00:30,840
we're going to make sure we are documenting our procedures,
14

14

00:00:30,840  -->  00:00:32,310
putting resources in place,
15

15

00:00:32,310  -->  00:00:34,110
and the different procedures in place,
16

16

00:00:34,110  -->  00:00:36,060
as well as conducting training.
17

17

00:00:36,060  -->  00:00:37,710
All of this is really important to us
18

18

00:00:37,710  -->  00:00:39,750
because it's going to make sure that we're ready to respond
19

19

00:00:39,750  -->  00:00:41,910
when an incident occurs.
20

20

00:00:41,910  -->  00:00:44,430
For example, most organizations are going to have
21

21

00:00:44,430  -->  00:00:47,640
instant response plans on file and ready to go.
22

22

00:00:47,640  -->  00:00:49,860
Essentially, these are your war plans.
23

23

00:00:49,860  -->  00:00:51,360
When you see something happen,
24

24

00:00:51,360  -->  00:00:53,430
you can look up what do you do in response
25

25

00:00:53,430  -->  00:00:55,200
to that particular thing.
26

26

00:00:55,200  -->  00:00:56,760
For instance, maybe you're going to be dealing
27

27

00:00:56,760  -->  00:00:59,790
with a DDoS attack, or a virus or a worm outbreak,
28

28

00:00:59,790  -->  00:01:02,790
or a fishing attack, or data exfiltration,
29

29

00:01:02,790  -->  00:01:04,950
whatever it is you're going to have different responses
30

30

00:01:04,950  -->  00:01:07,410
and different procedures for each of those things.
31

31

00:01:07,410  -->  00:01:09,150
And so as part of your detection later on,
32

32

00:01:09,150  -->  00:01:11,730
you're going to classify what that incident is
33

33

00:01:11,730  -->  00:01:13,350
and then respond appropriately.
34

34

00:01:13,350  -->  00:01:14,610
But here in preparation,
35

35

00:01:14,610  -->  00:01:16,860
this all happens before there's an incident.
36

36

00:01:16,860  -->  00:01:19,860
We have to have these standard steps ready to go
37

37

00:01:19,860  -->  00:01:22,530
that are tested, and we're ready to respond.
38

38

00:01:22,530  -->  00:01:24,600
So one of the best ways to do this
39

39

00:01:24,600  -->  00:01:27,000
is making sure you have a playbook.
40

40

00:01:27,000  -->  00:01:29,760
Now a playbook is a standard operating procedure.
41

41

00:01:29,760  -->  00:01:32,190
And it tells our junior analysts and incident handlers
42

42

00:01:32,190  -->  00:01:33,780
exactly what they should do
43

43

00:01:33,780  -->  00:01:36,000
in response to different scenarios.
44

44

00:01:36,000  -->  00:01:37,710
Now if you don't have these already,
45

45

00:01:37,710  -->  00:01:39,180
you can actually go to a website
46

46

00:01:39,180  -->  00:01:42,450
known as incidentresponse.com/playbook.
47

47

00:01:42,450  -->  00:01:43,590
And when you go there,
48

48

00:01:43,590  -->  00:01:46,380
you're going to click on I want to make a plan.
49

49

00:01:46,380  -->  00:01:47,220
Once you get there,
50

50

00:01:47,220  -->  00:01:48,690
you're going to find a Playbook gallery
51

51

00:01:48,690  -->  00:01:52,050
that has a bunch of playbooks already created for you.
52

52

00:01:52,050  -->  00:01:54,390
For instance, let's take a look at Phishing.
53

53

00:01:54,390  -->  00:01:55,710
If we click on Phishing,
54

54

00:01:55,710  -->  00:01:57,718
it will open up and give us a document
55

55

00:01:57,718  -->  00:01:59,730
that's about 10 or 12 pages
56

56

00:01:59,730  -->  00:02:01,650
that tells us exactly what we should do
57

57

00:02:01,650  -->  00:02:03,180
in terms of Phishing.
58

58

00:02:03,180  -->  00:02:04,020
Now as it goes through,
59

59

00:02:04,020  -->  00:02:06,600
it's going to tell us how we can automate our response,
60

60

00:02:06,600  -->  00:02:07,950
how we can detect it,
61

61

00:02:07,950  -->  00:02:09,420
what actions we should take.
62

62

00:02:09,420  -->  00:02:12,540
And each part it has a flow chart that gives us the actions.
63

63

00:02:12,540  -->  00:02:14,850
For instance, we can go through preparation
64

64

00:02:14,850  -->  00:02:16,740
and how we can determine what we're going to do
65

65

00:02:16,740  -->  00:02:17,940
and how we're going to train people,
66

66

00:02:17,940  -->  00:02:19,230
and how we're going to do interviews
67

67

00:02:19,230  -->  00:02:20,910
with all the different functions.
68

68

00:02:20,910  -->  00:02:21,930
And as we go through that,
69

69

00:02:21,930  -->  00:02:23,970
we have internal and external paths.
70

70

00:02:23,970  -->  00:02:26,100
And then we can move into our detection phase
71

71

00:02:26,100  -->  00:02:27,390
and it shows us all the different ways
72

72

00:02:27,390  -->  00:02:30,120
that we can detect this type of a phishing attack.
73

73

00:02:30,120  -->  00:02:32,400
And then, we go into our analysis phase.
74

74

00:02:32,400  -->  00:02:33,609
What type of things are we looking for
75

75

00:02:33,609  -->  00:02:36,630
as we're trying to triage and categorize this?
76

76

00:02:36,630  -->  00:02:38,640
And then we go into our containment phase.
77

77

00:02:38,640  -->  00:02:40,800
How are we going to stop this phishing attack?
78

78

00:02:40,800  -->  00:02:42,720
And then we can look at eradication.
79

79

00:02:42,720  -->  00:02:45,120
How are we going to triage it and confirm the report?
80

80

00:02:45,120  -->  00:02:47,160
What kind of communications we're going to have?
81

81

00:02:47,160  -->  00:02:48,540
How are we going to eradicate a malware
82

82

00:02:48,540  -->  00:02:50,970
that may have been download as part of this phishing attack
83

83

00:02:50,970  -->  00:02:52,320
and things like that?
84

84

00:02:52,320  -->  00:02:54,030
And then we move into our recovery phase.
85

85

00:02:54,030  -->  00:02:56,760
And then after that, we move into our post-incident phase
86

86

00:02:56,760  -->  00:02:59,010
and it tells us all the things we need to do.
87

87

00:02:59,010  -->  00:03:00,900
Now again, I went through this very quickly
88

88

00:03:00,900  -->  00:03:02,640
because you don't need to know all the details
89

89

00:03:02,640  -->  00:03:05,280
of all these flow charts that I went through on the screen.
90

90

00:03:05,280  -->  00:03:06,840
But the important thing is to realize
91

91

00:03:06,840  -->  00:03:09,600
that you can get these type of playbooks as a starting point
92

92

00:03:09,600  -->  00:03:12,150
and then customize them for your organization.
93

93

00:03:12,150  -->  00:03:13,290
At the end of the playbook,
94

94

00:03:13,290  -->  00:03:15,210
it's even going to give you some different things
95

95

00:03:15,210  -->  00:03:16,200
that you should be doing
96

96

00:03:16,200  -->  00:03:18,510
such as what does a proactive response look like?
97

97

00:03:18,510  -->  00:03:20,190
What does a quick containment look like?
98

98

00:03:20,190  -->  00:03:21,870
What does effective remediation look like?
99

99

00:03:21,870  -->  00:03:24,180
And what should your action plan be?
100

100

00:03:24,180  -->  00:03:25,890
All of this is information that's contained
101

101

00:03:25,890  -->  00:03:27,330
inside this playbook
102

102

00:03:27,330  -->  00:03:30,840
and allows a junior analyst to do this work very quickly
103

103

00:03:30,840  -->  00:03:32,550
because they can follow these flow charts
104

104

00:03:32,550  -->  00:03:34,560
and know exactly what to do.
105

105

00:03:34,560  -->  00:03:36,060
Now in addition to the playbooks,
106

106

00:03:36,060  -->  00:03:37,710
it's also important for us to know
107

107

00:03:37,710  -->  00:03:40,170
who we're going to call as we start escalating things
108

108

00:03:40,170  -->  00:03:41,730
and notifying people,
109

109

00:03:41,730  -->  00:03:43,710
and this is a really important thing to ask.
110

110

00:03:43,710  -->  00:03:45,150
Who are we going to call?
111

111

00:03:45,150  -->  00:03:47,520
And no, the answer is not "Ghostbusters".
112

112

00:03:47,520  -->  00:03:51,060
Instead, the answer is, we're going to consult our call list.
113

113

00:03:51,060  -->  00:03:53,100
Now a call list is a predefined list
114

114

00:03:53,100  -->  00:03:56,040
of instant response contacts in hierarchical order
115

115

00:03:56,040  -->  00:03:58,650
for notification and escalation.
116

116

00:03:58,650  -->  00:04:00,210
Essentially, if you're the analyst
117

117

00:04:00,210  -->  00:04:01,680
and you're working at three in the morning
118

118

00:04:01,680  -->  00:04:03,150
and you detect something,
119

119

00:04:03,150  -->  00:04:04,470
who are you going to call?
120

120

00:04:04,470  -->  00:04:05,790
Who are you going to wake up?
121

121

00:04:05,790  -->  00:04:06,990
Are you going to use a phone?
122

122

00:04:06,990  -->  00:04:08,040
Are you going to use a landline,
123

123

00:04:08,040  -->  00:04:09,780
a cell phone, a satellite phone?
124

124

00:04:09,780  -->  00:04:11,010
What about email?
125

125

00:04:11,010  -->  00:04:13,230
Is it going to be a corporate account or a personal account?
126

126

00:04:13,230  -->  00:04:15,750
Well, all of this depends on what your plan says
127

127

00:04:15,750  -->  00:04:17,820
and how you want to make contact.
128

128

00:04:17,820  -->  00:04:19,590
Now the reason why this is so important
129

129

00:04:19,590  -->  00:04:21,840
is because if that incident happens to be
130

130

00:04:21,840  -->  00:04:23,970
where an attacker has gotten into your systems
131

131

00:04:23,970  -->  00:04:25,710
and they have control of your network,
132

132

00:04:25,710  -->  00:04:27,450
you don't want to send an email over that network
133

133

00:04:27,450  -->  00:04:29,010
because you're going to tip your hand
134

134

00:04:29,010  -->  00:04:30,390
and let the adversary know
135

135

00:04:30,390  -->  00:04:32,340
that you've detected them in your network.
136

136

00:04:32,340  -->  00:04:35,160
So you need to have secondary and tertiary ways
137

137

00:04:35,160  -->  00:04:36,720
of contacting people.
138

138

00:04:36,720  -->  00:04:39,030
Your call list is going to help you define that.
139

139

00:04:39,030  -->  00:04:40,110
Who are you going to call?
140

140

00:04:40,110  -->  00:04:42,240
When are you going to call them, and at what level?
141

141

00:04:42,240  -->  00:04:45,390
Are you going to call your manager or your manager's manager,
142

142

00:04:45,390  -->  00:04:48,000
or the director, or the CEO?
143

143

00:04:48,000  -->  00:04:49,560
The answer is, it depends.
144

144

00:04:49,560  -->  00:04:51,540
Depending on how bad the incident is,
145

145

00:04:51,540  -->  00:04:53,880
it will determine how high up the chain of command
146

146

00:04:53,880  -->  00:04:57,210
and how far up your organization you need to call.
147

147

00:04:57,210  -->  00:04:58,530
Another thing you need to work on
148

148

00:04:58,530  -->  00:04:59,970
inside the preparation phase
149

149

00:04:59,970  -->  00:05:02,370
is the creation of an incident form.
150

150

00:05:02,370  -->  00:05:04,440
Now an incident form is going to be used to record
151

151

00:05:04,440  -->  00:05:06,810
all the details about the reporting of an incident
152

152

00:05:06,810  -->  00:05:09,600
and assign it a case or a job number.
153

153

00:05:09,600  -->  00:05:12,870
And a lot of organizations, this has become a digital form
154

154

00:05:12,870  -->  00:05:15,300
or some kind of a SharePoint website or a database
155

155

00:05:15,300  -->  00:05:17,220
where it can collect all this information.
156

156

00:05:17,220  -->  00:05:18,780
In the old days, it was actually a form
157

157

00:05:18,780  -->  00:05:20,610
that was filled out with pen and paper.
158

158

00:05:20,610  -->  00:05:22,290
Regardless of which one you're using,
159

159

00:05:22,290  -->  00:05:23,550
you're going to have a lot of the same type
160

160

00:05:23,550  -->  00:05:24,690
of information though.
161

161

00:05:24,690  -->  00:05:26,400
You're going to have things like the date, the time,
162

162

00:05:26,400  -->  00:05:28,020
and the location of the incident
163

163

00:05:28,020  -->  00:05:29,910
and the detection of the incident.
164

164

00:05:29,910  -->  00:05:30,990
You're going to have the reporter
165

165

00:05:30,990  -->  00:05:33,810
and the incident handlers names and contact details.
166

166

00:05:33,810  -->  00:05:35,280
You're going to have things like how the incident
167

167

00:05:35,280  -->  00:05:36,930
was observed or detected.
168

168

00:05:36,930  -->  00:05:38,880
What was the log or the alert or the thing
169

169

00:05:38,880  -->  00:05:41,790
that made you think, "Ah, we have an incident here."
170

170

00:05:41,790  -->  00:05:44,400
We also are going to define what type of incident we have.
171

171

00:05:44,400  -->  00:05:46,530
Is this a worm, a data breach,
172

172

00:05:46,530  -->  00:05:49,290
a piece of malware, unauthorized privileges,
173

173

00:05:49,290  -->  00:05:50,550
or whatever the type of thing is?
174

174

00:05:50,550  -->  00:05:52,020
We want to put that down.
175

175

00:05:52,020  -->  00:05:53,970
And then, we're going to look at the scope of the incident.
176

176

00:05:53,970  -->  00:05:55,950
Is this a small scope or a big scope?
177

177

00:05:55,950  -->  00:05:57,690
Is it affecting the entire organization
178

178

00:05:57,690  -->  00:05:59,820
or just a small part of the organization?
179

179

00:05:59,820  -->  00:06:02,130
For instance, let's say you had a system error
180

180

00:06:02,130  -->  00:06:04,410
that was taking down your entire website.
181

181

00:06:04,410  -->  00:06:05,430
That'd be a big deal
182

182

00:06:05,430  -->  00:06:07,530
and it's probably going to go further up the chain of command
183

183

00:06:07,530  -->  00:06:08,970
than if you had something that was taking out
184

184

00:06:08,970  -->  00:06:10,710
maybe just the payroll system
185

185

00:06:10,710  -->  00:06:13,320
and it was three weeks before payroll is going to be due.
186

186

00:06:13,320  -->  00:06:14,940
All of these are issues we're going to have to address
187

187

00:06:14,940  -->  00:06:17,310
but depending on how big or small the issue is
188

188

00:06:17,310  -->  00:06:20,040
that's going to tell us what the scope of the incident is.
189

189

00:06:20,040  -->  00:06:22,290
And finally, we have to have the incident description
190

190

00:06:22,290  -->  00:06:23,580
and event logging.
191

191

00:06:23,580  -->  00:06:25,259
This is where we're going to have all the information we have
192

192

00:06:25,259  -->  00:06:26,640
about the incident.
193

193

00:06:26,640  -->  00:06:28,860
For example, if I'm working as an incident handler
194

194

00:06:28,860  -->  00:06:30,570
and somebody calls into the SOC
195

195

00:06:30,570  -->  00:06:32,287
and I'm taking down the report and they say,
196

196

00:06:32,287  -->  00:06:33,510
"I'm having some issues.
197

197

00:06:33,510  -->  00:06:35,340
I think there's malware on my system.
198

198

00:06:35,340  -->  00:06:38,010
As I'm moving my mouse to the right, it's going to the left.
199

199

00:06:38,010  -->  00:06:39,870
When I click on this, it doesn't work."
200

200

00:06:39,870  -->  00:06:41,190
Those are indications that there could be
201

201

00:06:41,190  -->  00:06:43,980
some kind of remote access Trojan on that system,
202

202

00:06:43,980  -->  00:06:46,320
so I can get that information from the user
203

203

00:06:46,320  -->  00:06:48,750
and then pass that information over to the incident handler
204

204

00:06:48,750  -->  00:06:49,890
or the incident responder
205

205

00:06:49,890  -->  00:06:52,380
who's going to work that specific case.
206

206

00:06:52,380  -->  00:06:53,610
As we're moving through the incident,
207

207

00:06:53,610  -->  00:06:55,560
this is all the information we want to gather
208

208

00:06:55,560  -->  00:06:56,880
so we have more information
209

209

00:06:56,880  -->  00:06:59,610
and we understand what happened when it happened
210

210

00:06:59,610  -->  00:07:02,040
and all the steps that have happened up to this point.
211

211

00:07:02,040  -->  00:07:03,540
So we pass it off to responder,
212

212

00:07:03,540  -->  00:07:06,600
they can continue that log and we can use that later on
213

213

00:07:06,600  -->  00:07:08,750
as a way to go back and look at this event.
