1
00:00:00,120 --> 00:00:01,770
In this lesson we're going to talk

2
00:00:01,770 --> 00:00:03,510
about automated reports.

3
00:00:03,510 --> 00:00:05,040
Now, an automated report is a report

4
00:00:05,040 --> 00:00:07,110
that's going to be generated by your computer system

5
00:00:07,110 --> 00:00:08,940
automatically on your behalf.

6
00:00:08,940 --> 00:00:11,070
For example, you might have an antivirus software

7
00:00:11,070 --> 00:00:13,290
that is going to be run once an hour.

8
00:00:13,290 --> 00:00:15,270
And every hour it's going to scan your system

9
00:00:15,270 --> 00:00:16,350
and if it finds anything

10
00:00:16,350 --> 00:00:17,670
it's going to send that as a report

11
00:00:17,670 --> 00:00:19,800
back to your security operation center.

12
00:00:19,800 --> 00:00:21,300
Or you may have some sort

13
00:00:21,300 --> 00:00:23,945
of an endpoint detection response capability on your system

14
00:00:23,945 --> 00:00:26,880
and it will go out and continually be sending out a report

15
00:00:26,880 --> 00:00:29,340
once a day back to your security operation center

16
00:00:29,340 --> 00:00:31,290
so they can know what the status is of that machine

17
00:00:31,290 --> 00:00:33,810
and anything that was suspicious during that day.

18
00:00:33,810 --> 00:00:36,690
Here's an example of an automated security incident report

19
00:00:36,690 --> 00:00:38,250
that was generated by an endpoint

20
00:00:38,250 --> 00:00:39,840
in detection response capability

21
00:00:39,840 --> 00:00:42,060
that I've used in one of my previous networks.

22
00:00:42,060 --> 00:00:43,800
Now here you're going to see some basic fields

23
00:00:43,800 --> 00:00:46,380
such as the report ID, the generation date,

24
00:00:46,380 --> 00:00:48,810
the report period, and the prepared by.

25
00:00:48,810 --> 00:00:51,420
In this case, the report ID was 54738.

26
00:00:51,420 --> 00:00:54,480
The generation date was November 12th, 2023,

27
00:00:54,480 --> 00:00:57,240
and the report period was the entire 24 hour period

28
00:00:57,240 --> 00:01:00,660
of November 12th, starting at 0:00:00

29
00:01:00,660 --> 00:01:03,420
going to 23:59:59 seconds,

30
00:01:03,420 --> 00:01:05,250
which would be 11:59 p.m.

31
00:01:05,250 --> 00:01:07,140
for those of us who work in America.

32
00:01:07,140 --> 00:01:08,610
Now, when we look at the prepared by

33
00:01:08,610 --> 00:01:10,230
this would normally have an analyst name

34
00:01:10,230 --> 00:01:12,540
or if it was shared by the system automatically

35
00:01:12,540 --> 00:01:13,680
just like this one was

36
00:01:13,680 --> 00:01:15,450
you would see something like automated report

37
00:01:15,450 --> 00:01:17,340
or automated reporting system.

38
00:01:17,340 --> 00:01:19,500
Next, there'll be some sort of an executive summary

39
00:01:19,500 --> 00:01:21,540
that will tell you a little bit about the report.

40
00:01:21,540 --> 00:01:23,610
In this case, it says that this automated report

41
00:01:23,610 --> 00:01:25,221
identifies a critical security incident

42
00:01:25,221 --> 00:01:27,900
indicative of a potential network breach.

43
00:01:27,900 --> 00:01:30,150
The report highlights suspicious file access patterns

44
00:01:30,150 --> 00:01:31,680
and multiple network requests

45
00:01:31,680 --> 00:01:34,080
to known malicious external IP addresses.

46
00:01:34,080 --> 00:01:35,493
Now, the great thing about this executive summary

47
00:01:35,493 --> 00:01:37,620
is you can read that and then determine

48
00:01:37,620 --> 00:01:38,940
is this worth more of your time

49
00:01:38,940 --> 00:01:41,130
to go further down and read more about it?

50
00:01:41,130 --> 00:01:43,193
For example, if you're not the network analysis person,

51
00:01:43,193 --> 00:01:45,510
this may not be the report for you to look at.

52
00:01:45,510 --> 00:01:47,310
You may want to send this over to that person

53
00:01:47,310 --> 00:01:49,650
while you work on something else like a malware analysis

54
00:01:49,650 --> 00:01:51,150
if that's what your position is.

55
00:01:51,150 --> 00:01:53,040
So the executive summary is very helpful

56
00:01:53,040 --> 00:01:54,750
summarize what is in this report

57
00:01:54,750 --> 00:01:56,490
because these reports could be one page long,

58
00:01:56,490 --> 00:01:59,280
two pages long, five pages long, 10 pages long,

59
00:01:59,280 --> 00:02:01,710
or even 100 pages long depending on the amount of activity

60
00:02:01,710 --> 00:02:02,670
in your network.

61
00:02:02,670 --> 00:02:04,320
In this case, the sample report I have

62
00:02:04,320 --> 00:02:05,790
is only two pages long

63
00:02:05,790 --> 00:02:07,590
so the executive summary is very short

64
00:02:07,590 --> 00:02:09,720
and we're only going to look at about four different incidents

65
00:02:09,720 --> 00:02:11,760
that were logged inside of this report.

66
00:02:11,760 --> 00:02:14,430
Now, the first one we have was labeled as a critical alert

67
00:02:14,430 --> 00:02:15,720
because it was a suspicious file

68
00:02:15,720 --> 00:02:17,340
access pattern was detected.

69
00:02:17,340 --> 00:02:18,480
You could see the timestamp.

70
00:02:18,480 --> 00:02:22,920
This happened on November 12th, 2023 at 4:53 a.m.

71
00:02:22,920 --> 00:02:25,290
Right there that's already something that's suspicious to me

72
00:02:25,290 --> 00:02:28,110
because 4:53 a.m. is outside of the normal working hours

73
00:02:28,110 --> 00:02:29,280
for this organization.

74
00:02:29,280 --> 00:02:31,383
This organization keeps normal banking hours

75
00:02:31,383 --> 00:02:34,290
between nine and five and so anything outside of that

76
00:02:34,290 --> 00:02:36,180
would look a little suspicious to us.

77
00:02:36,180 --> 00:02:39,210
Then we can see what user was involved, in this case jdoe,

78
00:02:39,210 --> 00:02:41,026
and we see the system file server three.

79
00:02:41,026 --> 00:02:42,533
We can then see the details about it,

80
00:02:42,533 --> 00:02:45,720
which was multiple rapid file access attempts were detected

81
00:02:45,720 --> 00:02:48,360
and the behavior matches known ransomware footprints.

82
00:02:48,360 --> 00:02:49,380
The action taken,

83
00:02:49,380 --> 00:02:51,636
the user account was suspended automatically by our system,

84
00:02:51,636 --> 00:02:54,690
the affected system was kicked off the network and isolated

85
00:02:54,690 --> 00:02:56,661
and the initiated data backup procedures

86
00:02:56,661 --> 00:02:59,230
as part of our incident response playbook actions.

87
00:02:59,230 --> 00:03:01,140
Next, we had a high alert,

88
00:03:01,140 --> 00:03:03,110
which was an excessive admin login failures,

89
00:03:03,110 --> 00:03:05,880
and again, this happened on the 12th of November,

90
00:03:05,880 --> 00:03:08,250
and this time at 9:34 a.m.

91
00:03:08,250 --> 00:03:09,584
This happened on our main controller

92
00:03:09,584 --> 00:03:11,400
and this happened from the admin user

93
00:03:11,400 --> 00:03:13,350
because it was an admin attempt to log in.

94
00:03:13,350 --> 00:03:14,670
And this was on the main controller,

95
00:03:14,670 --> 00:03:16,680
which is our domain controller for this network.

96
00:03:16,680 --> 00:03:18,960
We see that there was over 20 failed login attempts

97
00:03:18,960 --> 00:03:20,550
in just under five minutes

98
00:03:20,550 --> 00:03:24,630
from the IP address of 192.168.1.105.

99
00:03:24,630 --> 00:03:26,670
That IP address is an internal IP

100
00:03:26,670 --> 00:03:28,620
so that tells me we may have an insider threat

101
00:03:28,620 --> 00:03:30,960
or we have somebody who's already exploited our network

102
00:03:30,960 --> 00:03:32,520
on one of our machines through something

103
00:03:32,520 --> 00:03:34,440
like a social engineering or phishing attempt

104
00:03:34,440 --> 00:03:36,900
and now they're trying to break into our domain controller.

105
00:03:36,900 --> 00:03:39,270
The action taken was that IP address was blocked

106
00:03:39,270 --> 00:03:40,981
so that communication can no longer happen

107
00:03:40,981 --> 00:03:43,799
and the admin account password was automatically reset

108
00:03:43,799 --> 00:03:45,660
by our system because again,

109
00:03:45,660 --> 00:03:47,520
we're using automated and orchestrated ways

110
00:03:47,520 --> 00:03:50,190
to respond to some of these minor security incidents.

111
00:03:50,190 --> 00:03:51,789
The third one we have is a moderate alert.

112
00:03:51,789 --> 00:03:53,910
This was unusual outbound traffic,

113
00:03:53,910 --> 00:03:56,550
and it occurred at 1:45 in the afternoon

114
00:03:56,550 --> 00:03:59,040
and the system was database server zero two.

115
00:03:59,040 --> 00:04:00,690
We saw a large amount of data transfer

116
00:04:00,690 --> 00:04:05,250
going to IP address 172.217.1.14

117
00:04:05,250 --> 00:04:07,890
and this was flagged in our threat intelligence feeds.

118
00:04:07,890 --> 00:04:09,871
The action taken, the network connection was terminated,

119
00:04:09,871 --> 00:04:12,266
and traffic contents were placed under review.

120
00:04:12,266 --> 00:04:13,350
At that point,

121
00:04:13,350 --> 00:04:15,330
this would notify our security operation center

122
00:04:15,330 --> 00:04:16,260
and they'll be able to go in

123
00:04:16,260 --> 00:04:18,750
and do the additional cybersecurity analysis

124
00:04:18,750 --> 00:04:20,785
on this incident to see was it malicious,

125
00:04:20,785 --> 00:04:23,070
suspicious, or was it benign?

126
00:04:23,070 --> 00:04:23,903
And it may have just been

127
00:04:23,903 --> 00:04:25,290
that we are backing up our database server,

128
00:04:25,290 --> 00:04:27,090
in which case it would've been benign

129
00:04:27,090 --> 00:04:29,243
if we were backing it up to an offsite cloud backup.

130
00:04:29,243 --> 00:04:31,707
But as we analyze this we can then determine

131
00:04:31,707 --> 00:04:34,050
was this really something that was a problem

132
00:04:34,050 --> 00:04:35,556
or is it something that was allowed

133
00:04:35,556 --> 00:04:37,679
because it was part of our backup strategy?

134
00:04:37,679 --> 00:04:40,170
The next thing we're going to look at is on page two,

135
00:04:40,170 --> 00:04:41,280
which is our fourth alert

136
00:04:41,280 --> 00:04:42,660
and this is an informational alert,

137
00:04:42,660 --> 00:04:44,203
which just says software was installed.

138
00:04:44,203 --> 00:04:47,040
Now in general, software being installed is not a big deal,

139
00:04:47,040 --> 00:04:49,770
but we do want to at least log it so we know what happened.

140
00:04:49,770 --> 00:04:50,610
Now as we look at this,

141
00:04:50,610 --> 00:04:52,800
this happened at 6:53 in the evening.

142
00:04:52,800 --> 00:04:56,100
The user was msmith and it happened on Workstation 22.

143
00:04:56,100 --> 00:04:59,250
The software that was installed is called FileZilla FTP

144
00:04:59,250 --> 00:05:02,460
and the file hash was not matching a known safe version.

145
00:05:02,460 --> 00:05:03,930
Now, this doesn't mean that this was bad.

146
00:05:03,930 --> 00:05:05,827
It may have been that this user msmith

147
00:05:05,827 --> 00:05:08,130
went to the internet and downloaded FileZilla

148
00:05:08,130 --> 00:05:09,300
and installed it themself,

149
00:05:09,300 --> 00:05:11,490
which may have been against our acceptable use policy,

150
00:05:11,490 --> 00:05:14,130
but doesn't necessarily mean it was an attacker hacking us.

151
00:05:14,130 --> 00:05:16,380
So we'd want to investigate it and figure it out.

152
00:05:16,380 --> 00:05:18,150
In this case, we could see the action taken.

153
00:05:18,150 --> 00:05:19,500
The software execution was blocked

154
00:05:19,500 --> 00:05:21,510
because we're using application whitelisting

155
00:05:21,510 --> 00:05:22,818
and the user was contacted to verify

156
00:05:22,818 --> 00:05:24,330
that they tried to do it.

157
00:05:24,330 --> 00:05:26,107
And if we called up msmith and they said,

158
00:05:26,107 --> 00:05:27,420
"Oh yes, I just tried to install it,"

159
00:05:27,420 --> 00:05:29,580
we'd say, "Oh, bad, don't do that again.

160
00:05:29,580 --> 00:05:30,870
Next time, call the service desk

161
00:05:30,870 --> 00:05:32,580
and we'll install the software for you,"

162
00:05:32,580 --> 00:05:34,768
and we can just file this away as a non-issue.

163
00:05:34,768 --> 00:05:36,900
But if he said, "I didn't do that,"

164
00:05:36,900 --> 00:05:37,830
and we start looking into it

165
00:05:37,830 --> 00:05:39,360
and he wasn't even at work that time,

166
00:05:39,360 --> 00:05:41,100
this means that his account may have been compromised

167
00:05:41,100 --> 00:05:42,660
and we'd have to look into that further.

168
00:05:42,660 --> 00:05:44,130
So these are the kind of things you can find

169
00:05:44,130 --> 00:05:45,562
inside of your automated reports.

170
00:05:45,562 --> 00:05:48,240
After that, you'll have the incident analysis.

171
00:05:48,240 --> 00:05:49,740
And you can see here we have threat trends,

172
00:05:49,740 --> 00:05:51,660
user behavior and data flow anomalies.

173
00:05:51,660 --> 00:05:53,919
We then have some security recommendations of what we can do

174
00:05:53,919 --> 00:05:56,670
based on the reports that we saw in this daily report,

175
00:05:56,670 --> 00:05:58,590
And then our conclusion where we basically summarize

176
00:05:58,590 --> 00:06:00,120
what we did, what we saw,

177
00:06:00,120 --> 00:06:01,800
and what things need to be further looked at

178
00:06:01,800 --> 00:06:03,257
over the next couple of work days.

179
00:06:03,257 --> 00:06:05,460
And then if we have any kind of appendix to this,

180
00:06:05,460 --> 00:06:07,500
it may include things like snippets of the logs

181
00:06:07,500 --> 00:06:09,660
to show us what was installed and what happened.

182
00:06:09,660 --> 00:06:11,374
We could see a list of the IPs and domains involved

183
00:06:11,374 --> 00:06:12,769
and other things like that.

184
00:06:12,769 --> 00:06:15,523
All of this is data that can be put into the security report

185
00:06:15,523 --> 00:06:17,409
and using automation and orchestration,

186
00:06:17,409 --> 00:06:20,250
we can not only look for these things and get reports on it,

187
00:06:20,250 --> 00:06:22,289
but we can actually act on them in real time

188
00:06:22,289 --> 00:06:24,276
and this way we can mitigate some of these incidents

189
00:06:24,276 --> 00:06:26,490
before they become a bigger issue for us

190
00:06:26,490 --> 00:06:29,343
and cause a wide scale data breach or network outage.

