1/75
Google Cybersecurity Course 6 (Sound the Alarm: Detection and Response) Module 1 (Introduction to detection and incident response)
Name | Mastery | Learn | Test | Matching | Spaced | Call with Kai | Chat |
|---|
No analytics yet
Send a link to your students to track their progress
bored
“Every day is something new, and I never get _____.”
life experience
“Cybersecurity is interesting because you can really bring your entire ____ ___________ to cybersecurity.”
Be assertive, have a plan, ask for help
Tips when looking for a mentor
Identify, Protect, Detect, Respond, Recover
Core functions of the NIST CSF
Preparation, Detection & Analysis, Containment Eradication & Recovery, Post-Incident Activity
NIST Incident Response Lifecycle
Incident
An occurrence that actually or imminently jeopardizes, without lawful authority, the confidentiality, integrity, or availability of information or an information system; or constitutes a violation or imminent threat of violation of law, security policies, security procedures, or acceptable use policies.
Event
An observable occurrence on a network, system, or device.
events
All security incidents are ______, but not all ______ are security incidents.
The 5 W’s of an incident
Who triggered the incident
What happened
When the incident took place
Where the incident took place
Why the incident occurred
Incident handler’s journal
A form of documentation used in incident response.
Preparation Planning/training process
Name the NIST lifecycle step
Set up uniform company email conventions
Create a collaborative, ethical environment where employees feel comfortable asking questions
Provide cybersecurity training on a quarterly basis
Detection and analysis
Name the NIST Lifecycle step
Identify signs of an incident
Filter external emails to flag messages containing attachments such as voicemails
Have an incident response plan to reference
Containment, eradication, and recovery
Name the NIST Lifecycle step
Communicate with sender to confirm the origin of the voice message
Provide employees with an easy way to report and contain suspicious messages
Post incident activity
Name the NIST Lifecycle step
Update the playbook to highlight additional red flags employees should be aware of.
Review processes and workflows related to permissions and adjust oversight of those permissions.
Computer security incident response teams
Aka CSIRT
CSIRT
A specialized group of security professionals that are trained in incident management and response.
Security analyst, Technical lead, Incident coordinator
Roles in CSIRT
Security analyst
A role in CSIRT. Their job is to investigate security alerts to determine if an incident has occurred. If an incident has been detected, the analyst will determine the criticality rating of the incident. Some incidents can be easily remediated by the security analyst and don’t require escalation.
Technical lead
A role in CSIRT. If an incident is highly critical, it gets escalated to the this role, who provide technical leadership by guiding security incidents through their lifecycle.
Incident coordinator
A role in CSIRT. During the incident lifecycle, this role tracks and manages the activities of CSIRT and other teams involved in the response effort. Their job is to ensure that incident response processes are followed and that teams are regularly updated on the incident status.
Incident Handling Team
Aka IHT.
SIRT, IHT
Other names for CSIRT.
Security Incident Response Team
Aka SIRT.
Ops Lead
Another name for Technical Lead
vulnerability
“Cybersecurity is very exciting. You never know when the next ____________ is going to be released.”
2021
When did the Log4j incident occur?
came together
“The entire company ____ ________ to investigate whether or not we were affected by this vulnerability.”
communicating
“The way to maintain clear and effective communication is by ___________ a lot.”
command, control, communication
For incident response to be effective and efficient, there must be clear ______, ______, and _______ of the situation to achieve the desired goal.
Command
Refers to having the appropriate leadership and direction to oversee the response.
Control
Refers to the ability to manage technical aspects during incident response, like coordinating resources and assigning tasks.
Communication
Refers to the ability to keep stakeholders informed.
Roles in CSIRTs
Security analyst
Technical lead
Incident coordinator
Security operations center
Aka SOC.
SOC
An organizational unit dedicated to monitoring networks, systems, and devices for security threats or attacks. Structurally, this unit often exists as its own separate unit of within a CSIRT. It is involved in various types of blue team activities, such a network monitoring, analysis, and response to incidents.
Tier 1 SOC analyst
The first tier. It contains the least experienced analysts who are known as level 1s (L1s). They are responsible for
Monitoring, reviewing, and prioritizing alerts based on criticality or severity
Creating and closing alerts using ticketing systems
Escalating alert tickets to Tier 2 or Tier 3
Tier 2 SOC analyst
The second tier comprises of more experienced analysts, or level 2s (L2s). They are responsible for:
Receiving escalated tickets from L1 and conducting deeper investigations
Configuring and refining security tools
Reporting to the SOC Lead
Tier 3 SOC lead
The third tier is composed of the leads, or level 3s (L3s). These highly experienced professionals are responsible for:
Managing the operations of their team
Exploring methods of detection by performing advanced detection techniques, such as malware and forensics analysis
Reporting to the SOC manager
SOC manager
The person at the top of the pyramid and responsible for:
Hiring, training, and evaluating the SOC team members
Creating performance metrics and managing the performance of the SOC team
Developing reports related to incidents, compliance, and auditing
Communicating findings to stakeholders such as executive management
Forensic investigators
Commonly L2s or L3s who collect, preserve, and analyze digital evidence related to security incidents to determine what happened.
Threat hunters
Typically L3s who work to detect, analyze, and defend against new and advanced cybersecurity threats using threat intelligence.
Policies, standards, procedures
Elements of a security plan
Incident response plan
A document that outlines the procedures to take in each step of incident response.
Elements of an incident plan
Incident response procedures
System information
Other documents
Detection and management tools, documentation tools, investigative tools
Incident response tool types
Documentation
Any form of recorded content that is used for a specific purpose.
Playbooks, Incident handler’s journals, Policies, Plans, Final reports
Types of documentation
Playbook
A manual that provides details about any operational action.
Google Docs, OneNote, Evernote, Notepad++
Word processor tools
Jira
Ticketing system
Google Sheets, Audio recorders, Cameras, Handwritten notes
Other documentation tools
Intrusion detection system
Aka IDS
IDS
An application that monitors system and network activity and produces alerts on possible intrusions
Intrusion prevention system
Aka IPS
IPS
An application that monitors system activity for intrusions and take action to stop the activity
Snort, Zeek, Kismet, Sagan, Suricata
IDS and IPS tools
Endpoint detection and response
Aka EDR
EDR
An application that monitors an endpoint for malicious activity. These tools are installed on endpoints. They collect endpoint activity data and perform behavioral analysis to identify threat patterns happening on an endpoint. They also use automation to stop attacks without the manual intervention of security professionals.
Open EDR, Bitdefender Endpoint Detection and Response, FortiEDR
Examples of EDR tools
Endpoint
Any device connected on a network.
Detection categories
A true positive
A true negative
A false positive
A false negative
A true positive
An alert that correctly detects the presence of an attack
A true negative
A state where there is no detection of malicious activity. This is when no malicious activity exists and no alert is triggered.
A false positive
An alert that incorrectly detects the presence of a threat. This is when an IDS identifies an activity as malicious, but it isn’t. These are an inconvenience for security teams because they spend time and resources investigating an illegitimate alert.
A false negative
A state where the presence of a threat is not detected. This is when malicious activity happens but an IDS fails to detect it. False negatives are dangerous because security teams are left unaware of legitimate attacks that they can be vulnerable to.
Security Information and Event Management
Aka SIEM
SIEM
An application that collects and analyzes log data to monitor critical activities in an organization
SIEM
car components:dashboard, network endpoints:___________
SIEM process
Collect and aggregate data
Normalize data
Analyze data
Security orchestration, automation, and response
Aka SOAR
SOAR
A collection of applications, tools, and workflows that uses automation to respond to security events.
Log analysis
The process of examining logs to identify events of interest.
Normalization
A process that converts data into a standard, structured format that is easily searchable.
Correlation
A part of the analysis process that involves the comparison of multiple log events to identify common patterns that indicate potential security threats.
Common SIEM tools
AlienVault OSSIM
Chronicle
Elastic
Exabeam
IBM QRadar Security Intelligence Platform
LogRhythm
Splunk
Aggregation
The process of gathering data from different sources and putting it in one centralized place.