Incident Response deep dive topics
We continuously document here various topics which will make the defenders prepared for handling a cyber incident.
We continuously document here various topics which will make the defenders prepared for handling a cyber incident.
Organizations of all sizes — from start-ups and large enterprises to governments and public sector organizations — can use FlexibleIR to get prepared for handling cyber attacks on premise and in the cloud. We help you build modern day cyber Resilience capabilities using our innovative visual approaches. We serve from IT to OT.
Deep Adversarial learning can be achieved through looking at Conti leaked Playbooks, Babuk Code, Black Bast chat leaks etc. This is in addition to the TTPs MITRE ATT&CK matrix.
Here we try to give steps on what a customer on realising that his/her bank is impacted by a crisis should ideally do. This could be a cyber attack like Ransomware or any man made or natural disaster. First is to remain calm. Monitor for any email/sms/social media updates from the Bank. Avoid panic with drawls of more than required/essential needs. Here is an clear […]
Annexure-E: Scenario-based Cyber Resilience Testing This is a sample template for Stock Exchange. REs are encouraged to make their scenarios in consultation with their IT Committee for REs. Sample scenarios that are targeted to cover in Cyber Response plan as well as Cyber Resiliency Testing(Types of Attack × Potential Targeted Time intervals- On Core Systems): WHY THIS HAS BEEN GROUPED INTO TIME ZONES Timing and […]
Being adversarial focused is key as part of the organization resiliency preparedness perspective. Here we give you links that you can do adversarial tracking regularly to move towards Predictive Ransomware Incident Response. IT Ransomware watch OT Ransomware groups General
If under attack, quickly do the scoping and plan for containment. Download few authoritative Write-Up (See below references) for the ABYSS Ransomware Variant(s) Encountered. Harvest additional Indicators from the Report(s). Mobilize the team and remember to take as much help as possible. You can customise our baseline playbooks Practice your TableTop exercise with FlexibleIR About This Threat Profile If you were impacted by this attack […]
PREPAREDNESS to handle an cyber attack if it happens NOW is key for every organisation. This is foundational to every Enterprise today. The engagements have to be FUN while learning. Humor can add in a lot of value. Below are a few strategies which we found very effective over the last 7 years. Customer engagement requires active participation from customers. FlexibleIR creates the channels and […]
Imagine a world where machines can diagnose diseases, write captivating novels, and even hold conversations that feel human. That’s the promise of Artificial Intelligence (AI) and Machine Learning (ML). AI refers to the broad field of computer science dedicated to creating intelligent machines, while Machine Learning is a specific technique where algorithms learn from data to improve their performance on a specific task. These technologies […]
A large number of Enterprises today run on Microsoft technologies, Azure cloud platform and security logging platforms as Sentinel. Responding diligently to alerts triggered due to abnormality and intrusion detections is key to avoid major crisis like Ransomware attacks and Data exfiltrations followed by publish on dark web. The below use cases are critical to identifying any of the early, middle, and end-stage operations of […]
We will ensure you are prepared for a cyber attack. Response Plans to Playbooks to TableTops - IT & OT - No SPAM.