October 11, 2024

EDR – Tampering by attackers

Problem: Endpoint detection and response (EDR) software has gained significant market share due to its ability to examine system state for signs of malware and attacker activity well beyond what traditional anti-virus software is capable of detecting. This deep inspection capability of EDRs has led to an arms race with malware developers who want to evade EDRs while still achieving desired goals, such as code […]

September 10, 2024

Incident Response – Need for continuous fine tuned detection and logging

Most major cyber attacks have a lot of early warning signals coming in, so early detection helps a lot and gives time for incident response. Logs for Incident Response https://www.first.org/resources/papers/conference2008/chuvakin-anton-slides.pdf Best practises for Event Logging Benefits of continuous and aggressive monitoring of your Event Logging:Enhanced Visibility: Gain a deeper understanding of network activity and potential threats.Faster Incident Response: Early Detection and quick response to security […]

August 25, 2024

LLM case studies to get Security Teams prepared

Enterprises are going to adopt a wide range of Generative AI use cases. The security teams need to understand them, and how they are built so they can eventually protect it better. Here we are learning from the perspective of Incident Response to cyber attacks on the AI platforms. Case study 1 – A great CTI tool – Neutocti This project gives a great insight […]

August 25, 2024

Generative AI – LLM – For Enterprise and AI incidents

FlexibleIR is an AI Incident response company. We help enterprises prepare foundationally to handle cyber attacks on their AI deployments. As part of the program, we ensure that enterprises have established strong AI governance. We provide Playbooks and TableTops to respond to malicious activity against AI systems and related data and services. These are most applicable to Enterprises deploying and operating externally developed AI systems […]

April 8, 2024

Incident response Case Studies and lessons learnt on the ground

Case studies help a lot in understanding how other companies respond to a crisis situation. What is the learning our organisation can take from it? Can we do a table top exercise using this as a scenario? Our approach – Reuse as much operational knowledge gained by your peers who have already handled attacks. Most of them are kind enough to help you provided you […]

November 15, 2023

Ransomware response training and drills

Preparedness is key to handling a massive cyber attack. Below are steps that we believe will aid you to be confident and respond effectively. Our approach of using visually easy and simple Playbooks will aid in developing the strong muscle memory required while mitigating an attack. First, know whom to call. Please first ensure you are able to quickly mobilize all the help required and […]

November 13, 2023

Cyber Crisis Management Blueprints

The art of understanding what a crisis is and managing it is key. Enterprises need to have clear Blueprints and Frameworks established to respond to a crisis like a Ransomware attack:1. Incident Response Plans with defined roles and responsibilities2. Playbooks with the course of actions (CoA) to respond – both technical and management levels.3. A system to regularly conduct TableTops and drills – clear after-action […]