logo

NJP

ServiceNow SecOps Mini-Series: The Overview | Share the Wealth

Import · Apr 20, 2022 · video

we're going to jump through the two main modules within security operations that you'll see as kind of the main selling point and the main interaction with customers and that will be security incident response and vulnerability response so a little bit of some some fast-paced slide wear and then we're going to jump right into platform and show you some stuff here show you what it is how you would work with it a couple of quick tips and tricks on success to success right success of use and success of implementation for customer base so the very first thing we're going to jump right into is a couple of definitions right when we talk about security operations as a whole again product suite several additional enhancing pieces like configuration compliance threat intelligence we're starting to see some machine learning predictive intelligence opportunities as well as as some of the the sweet offerings mature but it really all centers around these two processes into security incident response and vulnerability response so it's important to understand right just very brief review why both of these all of this falls within the tool set or kind of operational model of security operations often short to secops if you recall from two weeks ago our conversation on that on why really boils down to cost and impact to business 2021 of all times right with all the focus on security with all the focus on improving security posture and everything cost and impact of breach is still going through the roof one one of the slides that we saw in the prior deck based on ponemon and ibm studies response really you know having that that response plan and response strategy really saw cost drive down vulnerability side being able to prevent a weakness from being exploited in your environment before it is exploited cost deferred should an incident occur a security related incident occur having a well-practiced and well-planned uh response plan drove costs down astronomically and we can see that that's really what this entire tool set is looking for right we're looking to follow a plan a process and a program that allows us to detect find analyze and resolve vulnerabilities and security incidents or events in your environment faster so in order to do that we have to understand first what security and vulnerability really is so some definitions here that i grabbed you'll see a lot of reference throughout the servicenow security operations suite to nist and those are two organizing bodies that really set up some standards of of control and response within the technology in i.t space if you're not familiar with them already and one of the biggest documents you'll see really referenced out is sp800 or special publication 800 several versions of that so we'll see some definitions in here of what is a security incident right release really starts to boil down to incident causing harm attempt to breach attempt to compromise and attempt to maliciously change state of a system i think the key here right is security incident does not have to be and should not be only on breach right if we were to really drive in and really start to read the the fun bedtime reading documents of the nist documentation sans has some frameworks out there as well they really drive home the idea of event instead of incident a security event things like our firewall has detected malicious traffic should still be responded to the response plan and path will be different i think that's key i think it's one of the big security incident keys that we really drive home when we talk to this process right getting ahead of the curve detecting it and preventing it from being a breach is ultimate right should it become a breach we want some additional planning and that speaks to the context of why this isn't just standard incident right why why don't we just boil this into the incident response pro the itsm you know itil defined incident response programming process well that's because the level of event the type of event differs and therefore it requires a very coordinated and specific response program or a process and we'll see that here so this is the state process or kind of a picture idea of the nist misdefined and recommended state processes within the security incident response should we have an event that warrants security context we want to have good preparation we want to be able to detect and analyze that quickly contain it eradicate recover it all goes to so this you know you get the idea here right we contain it and then one of the important steps in in security incident response is also ensuring the the post we want to review what we did lessons learned and how do we go back and prepare our environment change our firewall state change our security posture add another tool if we need multi-factor authentication enabled or some of those types of so it is a recurrent continual loop but it is much less continual loop than what we'll see in vulnerability and what does this all boil down to really simplifying a very granular state of program event happens instead of having 18 steps 13 ways and 14 assignments we've really looked to set up a programmatic state flow and process for those events that have occurred and we'll see some of that in tool we'll see some of the ways that we can automate assignment based on asset or event type and we can also drive response through workflows and automations so then we talked about vulnerability response and one of the things that i do want to kind of segregate between these two we can almost in some ways think of a security incident as a reactive program something has been detected or something has occurred therefore go do vulnerability response yes there's a detection method to this but the detection the thing or or or weakness or or whatever that we are detecting is preventative right something is weak therefore go fix it before we have to react so vulnerability response is proactively responding to things found in our environment so to understand that we take a look at a definition so iso standardizations that are boiled into the nist response the sans response flows the frameworks really boiled down to helping to understand a vulnerability and in truth i think we've all heard it right it's a weakness it's bad code it's a port that's open right does not mean anything has happened but it could be and what we're really seeking in this life cycle is to shorten two key factors the vulnerability period of an organization time time between known vulnerability versus time to fix or resolve of that vulnerability and then also trying to prioritize that we'll see even in my own home lab environment how noisy vulnerability response can get because of the granularity of detection so we look to leverage the servicenow platform toolsets the business intelligence platform to risk rate rank prioritize assign and resolve those a lot quicker so having understood definitions you know vulnerability response finding those weaknesses assigning prioritizing and fixing and governing that state flow or that process security incident response detecting something against happening against our environment and responding quickly and appropriately to that as well as the governance of that flow we've seen these in our first deck that we that we talked through two weeks ago but this all really starts to leverage the servicenow platform throughout several months to make security and vulnerability an organization's effort an organization's quote unquote problem and that is simply because it's bigger than the security teams it's bigger than your your security operation centers or your socks or cyber response teams it's bigger than your vulnerability managers that that scan you know hunt and find these and it takes an organization to really fix this so we've seen all of these flows and we start to get the sense that there's a lot of interaction platform and external so just quickly reviewing the organization method of that right we get the idea that we feed all of this data this data feeds from all those tools one of the things that i like to speak to security incident and vulnerability response both in servicenow what is it it's the orchestration and automation and response engine we talked two weeks ago about that idea of source security orchestration automation and response but what is it not it's not the detection method right servicenow still is looking to leverage those tools that are out there that do their thing and do it well vulnerability scanners where there's a lot of investment in ensuring that they have insight and visibility into your environment we can connect in authenticated ways credentialed ways to the wide swath of environment that you have cloud and local and we can really query into that device much like we would do with discovery the key differentiation here when we talk about servicenow discovery and having that capability as as opposed to these additional tools is these tools have that additional layer of security knowledge they know what a vulnerability is what the particular signature or or key detection method for that vulnerability is something like uh port is open and you know in in the microsoft world you know hp local machine reg key has a value of one therefore vulnerable same thing when we talk about the security incident side right just because i as an end user open a command prompt and i type ping google that is not a security incident my tools might see that carbon black checkpoint you know firewalls etc might see and be able to log and track that traffic but now if 50 external users are pinging my services i want to know about that those tools know that signature those tools know that aspect of this but what they don't often know is your environment you're giving them an ip address to monitor you're giving them a specific thing to look at but what you're not giving them is the it and the business intelligence right asset ownership risk of asset in your environment posture other policies that might be in place and you're also not governing a response flow you're simply monitoring state so all of that right we look through that slide deck we see a lot of complicated interaction we see a lot of integration we see a lot of internal and external interaction to platform service now has done a really good job with the security operations suite of this obviously high level but kind of seven point path to success you'll notice across and this is across secops right you'll see in step three we do hear mention security incident and vulnerability that's important in this step path because you'll see that our very first step is service aware cmdb so this goes to configuration management csdm alignment some of those protocols and frameworks for asset x server is a windows device is owned by and supported by a specific team it's internal facing its external facing all of those types of attributes that we can assign to a device are very very helpful and useful but the additional layer above that is that service awareness this group of five servers runs our website runs our business banking portal runs our and i'm being careful here and being very generic because service can be defined in very specific ways but the key here is to understand we're not we're really looking at impact organization because when we talk about a vulnerability and when we talk about a security incident yes the incident entry point was a specific thing device or end point but by compromising that the compromise can now become widespread very simple and easy example is ransomware because a user clicked a link our initial impact or detection is probably a user clicked link the laptop or workstation that computer was uh or that that link was clicked on but the impact very quickly becomes replication of that ransomware across your environment so knowing what all those relationships are is a very important four customers that are cm what i'll say as cmdb light there are still ways to leverage the platform and to leverage device awareness as part of this implementation or the path to success and it really comes down to a maturity phasing oh you don't have cmdb now well guess what those security tools and those vulnerability tools happen to know a little bit about assets ci's and devices on your environment or in your environment therefore we can leverage that so i can't speak enough to cmdb cmdb cmdbcmdb when we talk about security operations but it's also important to know that there are ways to work within limited sets of data there so we go from talking about our cmdb our our device and service awareness to integration integration within security operations is very important integration within tool integration external tool as we talked about all of those tool sets so cmdb the conversation around that then the conversation around what tools are you using how many tools do you have what are they doing what are they responsible for carbon black does something specific versus splunk doing something specific in your environment versus your particular vulnerability scanners to that i have actually had customers and consumers of vulnerability response specifically you might often think you know one single scanner does it all and a lot of times it's not true i have implemented a customer that used all three key direct integration scanners at the same time qualis rapid seven and tenable all because of mergers acquisitions divestitures sub-customer environments maybe it's a customer that branches into federally regulated space etc so there is capability and it's important to understand all of those and how those interact we then get into the real meat of three four and five what we can really do with servicenow prioritization enrichment and governing the response six and seven are important but you often find that in a little bit of a more mature customer automation of the response right automatic deployment of fix automatic whitelist and blacklist uh against a firewall goes back to integrating with some of those tool sets and as with anything else making sure that we can see how we're doing via dashboards all right let's jump right in so i'm going to show you two environments only because of demo data and availability of integrations so i actually have a home lab i have somewhere around as a scannable endpoint here at home 50ish ip addresses that are scannable no that's not 50 physical devices and this is a great idea an example of how we can leverage that scanner to really query in and correlate all of that so i've also deployed rapid 7 scan engine in my environment so the first thing that i want to mention here because of demo i don't have a cmdb i have not gone through discovery efforts at home i've i have a mid server out there but i haven't actually set it all up taking the time to so i am a customer here that is very cmdb-lite but the first thing that we've done on the vulnerability response side is we've built we've set up our integration to our scanner some of the key things that we talked about when we talk about integration with scanning environment for vulnerability what is our interval of scan what is our volume of scan and how often you'll see and find that customers will scan segments of their environment differently this is a high priority data center we scan it every other day this is our internal inside of highly secured firewall you know corporate environment we scan it once a quarter hopefully they're doing more than that but because of that within each of our integration tools again i mentioned the three key ones qualis rapid 7 and 10able are all the integrations are all very well built by servicenow but there are others out there that are vendor provided like tanium microsoft now has a vulnerability scan solution that that they've written some integration rules for here as well so not boring you with the details of setting up and configuring the integration rest api whatever those needed credentials are but we govern this through scheduled integration runs three main key data elements within vulnerability response we need in order to to leverage the platform as a whole asset data i'm going to say asset generically because a lot of your external tools are calling it asset vulnerability data if you recall the definition that we talked about here a vulnerability by itself before we talk about impact in our environment is the weakness it's a weakness on or of asset or group of assets so we want to bring in those that data right you'll hear about things most recently log4 shell or log4j log4x as they're calling it now you heard some meltdown spectre we talk about the the print nightmare vulnerability of recent all of those are the vulnerability the vulnerabilities themselves right that definition of a vulnerability is going to tell us some key things it's going to tell us is it exploitable what's the risk what's the public facing not applied to your environment yet risk and then your scan data so we take the combination of that vulnerability and is it on your asset or on your device in your environment and we build scans with our scan detection environment so there are three key elements and so all of our integrations really boil down and start with those three elements vulnerability definitions asset and scan or vulnerable item so it's important that those are scheduled according to interval of of scanning in a customer's environment and how often they're updating their scanned data so we schedule that what does that start to look like we bring in welcome to demos they take forever when you don't want them to so we're going to bring in very first thing the vulnerable definition and i'm just going to randomly pick one here just because we're looking at this does not mean that this is in your environment right so we're building a library of of known signatures known things known weaknesses this can be vendor specific this can be more wide it can be you know the cve the weakness so on and with these comes some baseline risk scoring and rating we have all heard the press if we've if we've read any of the technical news around that log 4x stuff it was immediately rated critical why because of simplicity of and ease to exploit i could pass a url to any public-facing service and immediately exploit that vulnerability so on the public side before we know anything about that vulnerability in our environment we already know that we need to pay attention to it we have some varying levels of scores and it's very industry it's very vulnerability industry one of the key things we see is common vulnerability scoring system this is a agreed on industry matrix where our final score from 0 to 10 is computed by way of all of those different metrics is it exploitable how easily exploitable if it's exploitable how what can it jump is it only on that machine can we go beyond that machine with that exploit etc and that drives us up to a base score so we'll see that start to apply and there is a matrix around the the 0 to 10 that equals a none low medium high or critical but again this is just definition log for shell log4j critical because of ease of exploit so now we bring asset data in this is import a very critical path or critical part of security operations and specifically vulnerability response because we want to see the accuracy of the device we want to know device information for organizations that have spent a lot of time to invest in cmdb we want to make sure that our scan asset right ip address endpoint target of scan correlates over to our device in the cmdb to get that extra business intelligence how do we do that again not diving deep into the technical how to's of each of these but within the vulnerable within security operations and vulnerability response specifically we have lookup rules so these are going to match the raw data coming from our scan to our cmdb through a variety of methods we can see scripting we can see field matching and it's important to understand that we've walked through the cmdd so we find that device in your cmdd various ways ip address network cards related to the to that device so on and we correlate that so i'll give you a view into my environment here as i mentioned right around 50 devices some of these have the same ip4 such as my core router shared across several vlans but several devices in our environment because i don't have a cmdb defined in this instance you'll notice that they're all unmatched this is one important factor that i do like to show in a demo because we can still leverage this data as i mentioned cmdb very important really starts to build out our vulnerability response program really look to drive customers to get your cmdb correct and straight at least at least at a minimum device risk posture and device ownership devices is external is not external is in dmz is not in dmz and or supported by group something of that nature really goes far but again we have the ability to bring in that asset data from that scan data from our scanning environment and within that we also can bring in some of that data such as my rapid7 environment has this tagged as this is in jones home we might have multiple sites at data center one two three etc so we can get a very base asset view here and then the last data element that we bring in within our integration is vulnerable items so the vulnerable item here is exactly what we just talked about we brought in our asset we brought in our our vulnerability log4j log4shell print nightmare etc and now we're bringing in the scan result that says that a vulnerability log4x is found by our scanner on your asset and the asset is a macbook isn't as pi it is your nas is whatever these services and things are hey guess what my apple homepod is vulnerable imagine that so this is now the base starting point for building the vulnerability response tool in service now the first thing we see when we look at a vulnerable item is in my environment of 50 devices give or take most of these are actual actual you know nodes or clusters or or containers within shared service devices so 600 vulnerabilities here at home is is a little daunting imagine an organization that has 2 000 servers and 50 000 workstations that number is going to be astronomical and not uncommon to see millions or tens of millions of vulnerable items active open viewed waiting for response so there's several things that we do with that again honing in on that being noisy right the very first thing we're going to start to do is risk assign and set expectation of fix how do we risk so there are calculators that will take a look i open the right one i did all right here we go there are calculators that we can leverage that will start at that vulnerable item take a look at all those data points and elements that we talked about the external facing view the cvss or severity score right qualis or rapid7r tool says it's vulnerable because of x y and z attributes or it's critical because of x y and z attributes but then also leveraging servicenow oh this device is in your cm to be flagged as externally facing we're going to bump our risk up it has an exploit exploitability uh there's a known exploit bump the risk up so on and so forth right many different factors that we can go to we can start to talk about posture of the device relationships within the device uh is the device a part of a critical business service and this is where service awareness see that csdm framework and alignment of services what service what's the criticality of that service really start to come in at a base right what we're looking to do is leverage all of that intelligence and known data to tell our responders and tell our organization that this is the vulnerability you really need to look at right now this is the vulnerability you can you need to be aware of and you need to look at very quickly but not as quickly as this other one so we can condition we can build these out to every nth way to the to the sun it's important here that the organization understands what their risk calculations are and how we're arriving at a score so we build our vulnerable item risk using known data of the vulnerability and known data of our asset there are provisions we can do where as i mentioned we do track those that are still still found in your environment but not in your cmdb which is everything i have in here and we can still leverage that to build out a risk for you as with any anything else in the platform sort filter so on so i have a risk now i have my asset i have my vulnerability and i have a risk i have a base framework for response from there i'm going to assign this because i have information about the device because i have information about the type of vulnerability it might be i build out assignment rules that leverage that so i've built a couple of demo ones here first and foremost we want to get this the the intent to assignment here is visibility and response we want to get this this quickly to the people that are going to be fixing the vulnerability more often than not that's going to be the people that support the device so we leverage ci support group we could do ci assignment group you know an assignment field on that asset or ci but oftentimes we find that that's a struggle point that's non-discoverable that's something that configuration management programs and processes have to maintain over time and with many customers we may find inaccuracies or issues with that or we might find extenuating circumstances such as yes we want to leverage the ci support group but if it's exploitable we want it to go to a very specific subgroup of response so we can leverage that we're going to look here at we're looking first to make sure our rci on the vulnerability has a support group assign it to that if not maybe we're going to do ip based or location based etc many different conditions we can do and then we'd set our assignments and you'll see two different ways we can statically set this or we can leverage field on form field on table all right so we've got now a very good stellar awesome and amazing program built for all of these vulnerable items but we have too many sure i can come in here and i can say show me all my criticals show me all my eyes right and assign them but what's going to happen is you're in larger organizations you might find that you turn this on and you implement this and you set all this up and you literally have just assigned your network team 40 000 things to go fix yeah that's not going to happen you know information overwhelmed there and alert fatigue is going to set it in and they're just going to look at that and go yeah whatever okay we'll just fix it on the next patch and very quickly that becomes exploited and we now talk about security incident we don't want that so what we can leverage is this a function of roll-up or grouping for for anybody that's familiar with vulnerability response prior to the most recent version that was called vulnerability group it's now called remediation task because that's really what we're looking to do we're going to find common logic across these four common effort to fix common effort of ownership and we're going to group it into one single task that you can view look and do several things that we can leverage again it's the same thing with the risks the same thing with the ci and asset data we leverage all of that right type of is it exploitable yes or no that's going to define the grouping logic it's a known windows device and no network device it's a network device in a certain environment therefore group these together most often though we want to talk about grouping these in a way of how are we fixing it the intent to the group is fix and fix fast launching point to fix so we're not going to put a macbook that is managed by ibm bigfix with a windows machine that is managed or remediated by sccm in the same patching or in the same vulnerability response or remediation task or group we're going to want that type of logic in here so we build those rules out we can see an example here again not to get into how to build the rule but by function right we can group and condition this many many different ways i've kept this one simple i'm going to group everything i'm gonna i'm going to define my what will be grouped as anything i've got but i'm going to build my groups around the idea of ci class windows server linux you know network device etc i'm going to also build my group around if it's exploitable and who owns it simple idea and then we're going to assign it to whoever has been assigned the vulnerable item so if you recall as we've walked this demo we have somewhere around 600 vulnerabilities in here obviously we see some that have already been remediated or fixed but we have a law but if we take our grouping strategy now of those 600 we have seven things seven seven working things to fix why because all of these have the same fix we're going to take a look at this one because i've massaged the data for the point of demo but this particular grouping is my network devices it's not exploitable ignore a short description that's bad demo this would be adjusted default is however our criteria of grouping but you adjust that for the customer to be more friendly so essentially this is telling me we grouped it because we knew about the assignment these are ip firewalls and it's not exploitable so we immediately know something about what this grouping of work is and we apply a risk rating based on the items that are assigned and we assign it we can see here that roll up function now drives us to responding quickly all of this was done in an automated fashion we set up all those rules so every time we ingest the vulnerability data the asset data the ci data the scan results we build these out dynamically and now our vulnerability analysts our support groups and ownerships come in here they're assigned this task to now resolve they know this one happens to be low so in a larger environment yeah 600 to 6 that's awesome you're probably talking millions to thousands in a well sought out grouping strategy so you're still going to have thousands of vulnerability groups but these are much easier i from here i can see this happens to be the same asset the same device my core router i can see that it has all very similar if not same vulnerabilities on it right tls version 1 support so i probably want to go fix that that's an easy fix even though it's a low priority i'm going to go log into my router i'm going to deprecate my tls10 support in there and i'm going to turn on tls 3 i'm going to redeploy a certificate and i fix this cool so i've done that right several things we can do with this we can leverage automation orchestration you know orchestration tasks now that would trigger go fix go do patch fixing etc but you'll also notice that we have the ability here to jump right over to change it's a long demo to demo the change integration but the key here is change drives process i need to go you know i need to go determine impact i need to see if i need to do this as an emergency or standard change or normal change is there down time what's my impact across the organization awareness across the organization all that change management flow we create our change the vulnerability response and items are reflected you would see an awaiting implementation of change state we we now defer to change change is implemented it indicates that we have closed our or resolved our vulnerabilities so all of this is awesome and great but the key thing here is if we if we recall our life cycle this is a repeat right it's a trust but validate trust but verify so what are we doing right our end user base our assignment basis said that they have fixed or or patched or solutioned the fix but we're going to go right back around and we're going to rely on our scanner our scanner rapid7 goes and rescans the environment and tells me if each of these are really resolved or fixed so you'll see that you'll see that these will move through those varying states based on validation closed but validated and we'll see that idea of of waiting on our scanner to tell us all right so that's a end-to-end demo an idea of vulnerability response tucked in with some of the success factors right understanding the complexities here that there's a lot to factor it's important that we understand risk it's important that we understand what the organization's risk is we might find organizations that have a more specific risk focus because of their regulation or their industry segment they're in health care versus finance phenoms or you know manufacturing all are going to have those factors that are all part of factoring risk ownership assignment and response so we can see that tucked in here also is several and i'm not going to board we're all we're all service now folks in some form or fashion so i'm not going to drive through all the varying levels of reporting we all know what it can do there's a very good base for standard reporting as well as performance analytics reporting which i do not have active in this environment so you will see several different views reports and dashboards the important thing to understand here is that the base is there and we can leverage that to start to show risk factors what's at risk what's in process how well are we doing how many have we resolved over time how many hi low moderate have we resolved over time all right so that's vulnerability response so the natural and easy segue from vulnerability to security incident is where vulnerability response we're leveraging the idea of scan before scan find and resolve before it's exploited security incident is or being attempted to be exploited and think of it that way so if we go back and we look at one of these vulnerable items just going to go ahead and reopen this one you'll notice right on the vulnerable item we have a create security incident from a human factor let's say we're analyzing this and we see indications of x active exploit in our environment so we now are saying hey guys initiate your incident response plan for this vulnerability because it's being exploited obviously we still are going to fix our vulnerability but we're also doing the active portion of this all right so because a demo i don't have a fully demo-able security incident program set up in my environment here but point by and large the idea here is we bring over our asset data this is still important for a security incident event is occurring against this device ransomware on device malware detected virus detected uh malicious file user some user behavior you know user click the malicious link comes in and we start to build through a process you'll notice state flow each of these align to that secure that nist flow that we talked about here around the detect analyze contain eradicate recovery and post so we're going to drive this through a process but one of the things that we start to leverage with security incident response is the idea of response flow you'll hear these called run books in the environment i do not have any but as an example here in a security incident response program what we have done in a mature program is we've categorized security incidents or event types malicious file unauthorized access password compromise phishing spam loss of equipment theft guess what we even have copyright violation because that can lead to security issues so on and so forth so we've categorized these servicenow has done a good job of aligning a lot of these as at a parent level to some of the nist and sands overall generalized categories so when we brought this over from security incident we brought our from vulnerability we brought a categorization unpatched vulnerability on a vulnerable application being exploited we assigned this very quickly based on that categorization or asset data similar to vulnerability in that role and we've immediately queued up some analysis those run books then would define how we respond to this it's an unpatched vulnerability so we could talk a knowledge base article that says step one step two step three did user was this generated by user clicked link yes or no if yes right and what do we do with that we spin up flow and task again demo i don't have a lot of these built in here but we're going to spin up those tasks and response to those tasks can be internal to your security program or external compromised password password is compromised by a fellow employee we're probably going to go to the identity access management team and tell them to disable both user accounts change passwords and the provisions and stuff so that task is assigned and that task will govern the flow much like a any other response flow so one of the fun things with this as we move this generic task through each of these states indicate what we're doing right contain eradicate recover all within the phase of response life cycle making sure that it's not happening anymore stopping the threat eradicating it meaning it's not if it's malware if it's if the threat has deployed something in our environment getting rid of the the maliciousness recovering would also be getting rid of the maliciousness but on the aspect of restoring old files restoring backups getting the business back up and running and you'll notice that based on these state flows we govern that process to only allow you to move forward and back between for security life cycle for legality reasons for threat reasons we most likely never move back to an analysis state we are in containment that means we're already starting to adjust rules security things firewalls getting rid of malware blocking ip addresses and such so analysis doesn't make sense and should not be gone back to for various reasons all right so we've analyzed this i've intentionally skipped some of the automation and enrichment steps here in the response process we will show that in a moment but we've reached the end right and we'll notice that we don't go to close we go to this review state why post incident we want to gather some data from those that responded to this incident maybe it was me maybe it was yeah pick me later lazy development i'm going to pick sysadmin and i'm going to pick a couple other people here right so these people all did some factor something with this incident so we're going to send them a post-incident response survey and we're going to ask them to complete it what does this gather what does this do for us using the assessment and survey engine we build out questionnaire right based on type of incident was there was there a need for legal did we have to involve law enforcement et cetera so this becomes a archival record but it also becomes a an opportunity in our flow when we talk about and my deck has now jumped there we go when we talk about this loop back to prepare and back into that detection this is the exact state where based on our our gathering of data post fact how did we respond what did we do who did we involve did we talk with so and so such and such what is some of that evidence that it was really fixed right we can leverage that to now go back to our security team our tool ownerships and say look okay we really probably ought to implement x protocol we probably need to put in multi-factor authentication because the way this thing was compromised was by one single password so that's what this post-incident review gives us we will see the varying states we will see history but we will also ask for evidence questions did you talk to did you respond how did you respond was there a financial loss some of those types of things there's a base tool based survey in here but that is user customizable some of it will go to industry what is the what industry are you in are you highly regulated if you follow financial operations and your pci regulated customer because you do payment process heavy payment processing there are things that pci requires in a security program in order to be pci compliant and show that you are so you would gather these as part of your evidence of response once this has been completed by those respondents so we'll fly through one right and here's where you get the idea each of those phases oops and we now are going to respond and just like any other part of the assessment metric survey platform interactive based on you know conditions based on so on and so forth i don't know which ones or how many of these are required all right i just completed it do a little trick here and get rid of this user we're not going to wait on him to fill this out all right so our assessment has been completed and now can we really consider this to be truly closed we've gathered our evidence so one of the nice things with that security incident closure you'll notice here our our response for that post incident survey is stored and accessible by attachment where now we can get a historical view so auditors regulation going over to to some of the governance and compliance pieces of this this now starts to show us some of that protocol and program compliance lessons learned what did we adjust did we what was our our issue and delay so on and so forth so we've now completed a security incident in our environment and we have launched post incident and we've now gone back to those teams to respond appropriately to adjust our environment and lessen the the future state of this happening all right the additional pieces to this i have not necessarily mentioned because it required me switching over here but also because they're enrichment at a very baseline we get the idea here of security incident and vulnerability and what they do within security incident response just like with vulnerability we will leverage and want to leverage those tools that are out there so security incident response can ingest events and incidents from other tools like splunk like firewalls carbon black endpoint protection antivirus tools that will report we can ingest those in various ways we can do various things via email or otherwise to create those tools or to create those incident records we can also leverage threat and within the response cycle if one of these will open up and i know we're right at time so i'll show this very quickly that we can leverage lookbacks and searches we could send this information or specific indication you know iep address that was found fire file hash md5 hash etc that was found to send to other tools threat tools enrichment tools virus total have i been pwned augment that data so that now guess what on this threat on this incident hybrid analysis and virustotal both say it's a malicious i now know i need to respond with more impetus and more more priority to this in a slightly different way we also have things like other enrichment tools like mitre where we can see the framework of attack miter in and of itself could take a several hour demonstration to demo because it's a very complex framework all right so we've seen the tools we've seen the two main tools we've seen how we can at a very quick glance how we can leverage enrichment tools like virustotal have i been proponed we can log search back out to crowdstrike carbon black so on to see how where else we've seen this in our environment and respond appropriately so i know we are right at the 12 o'clock hour i will and open up to three four quick q a and if we don't have any questions everybody i do appreciate your time feel free to reach out as always as you are going through this or if you have any questions offline absolutely feel free to shoot it out and i will help correlate response thanks sir [Music] you

View original source

https://www.youtube.com/watch?v=drN-MqnvMN8