Memory hook: Contain harm while preserving what explains it.
Must remember
Preparation establishes contacts, authority, playbooks, logging, tools and exercises. Detection and analysis distinguish an event from an incident and establish scope. Containment limits damage; eradication removes the cause/persistence; recovery restores trustworthy service; lessons learned improve the system. These activities can overlap and repeat.
Use the scenario's authority and safety requirements. Isolate a compromised endpoint when appropriate, but do not automatically power it off: volatile evidence may matter. Human safety and urgent containment can outweigh evidence collection when the situation requires it. Engage legal, privacy and communications owners for reporting obligations and external statements.
Chain of custody records who collected, handled, transferred and stored evidence. Integrity hashes help demonstrate that a copy has not changed; they do not independently establish who collected it or whether collection was lawful. Preserve originals and work on validated copies where practical.
Volatile sources include running processes, memory and active network connections; disks and archived logs are generally less volatile. Collection order depends on the system and investigative purpose. Record synchronized timestamps, time zones, commands and methods. A legal hold suspends normal deletion for relevant material.
Threat hunting starts with a hypothesis and seeks evidence beyond existing alerts. Root-cause analysis asks why the incident was possible, not only which host was infected. Tabletop exercises test decisions and communication; simulations and technical exercises test execution.
Backups used for recovery must be known good, accessible and protected from the same compromise. Rebuilding without revoking stolen credentials or closing the original entry point invites recurrence.
Choose under exam pressure
| Requirement | Choice and reason |
|---|---|
| Suspected compromise with ongoing exfiltration | Authorized containment plus scoped evidence preservation. |
| Evidence may be needed in proceedings | Document custody and collection integrity. |
| Validate response coordination | Tabletop exercise with owners and decision points. |
Traps
- Reimaging first can destroy the explanation of a broader breach.
- An incident is not closed merely because alerts stop.
Active recall
1. Containment versus eradication?
Containment limits ongoing damage; eradication removes malicious components and causes.
2. What does chain of custody establish?
A documented history of possession and handling of evidence.
3. Does a matching hash prove legal collection?
No. It supports integrity, not legality or complete provenance.
4. Why revoke tokens after a rebuild?
Stolen credentials may remain usable independently of the cleaned host.
5. What makes lessons learned useful?
Assigning improvements, owners and verification rather than only writing a timeline.