mylamour / blog

Your internal mediocrity is the moment when you lost the faith of being excellent. Just do it.
https://fz.cool
61 stars 14 forks source link

Thoughts on Fast Incident Response(FIR) #79

Open mylamour opened 3 years ago

mylamour commented 3 years ago

About FireEye being attacked by APT. They showed a very sincere attitude. This is worthy of respect and learning. But for other companies how to deal with subsequent impact is a problem.

  1. Check the contents of the weapon library and make patches for the attack surface.
  1. Extract the IOC from the weapon library and make a scan on the whole assets.

According to Tencent's Security Laboratory, they have detected many new IOC

  1. Tracing the Corresponding Attacks and Make a Forensic Analysis.

The premise is that there are sufficient resources, and most cases can only meet the first two steps. Professional traceability analysts are not easy to find.

At the same time, don’t forget to follow the company’s internal regulations to initiate corresponding changes. For example:

It is still necessary to recruit professional security engineers and continuously optimize the security defense architecture and improve the emergency response process in order to achieve the fastest recovery measures. Win precious time difference in the war with the attacker. also for security engineers, solving problems should be value-driven, threat-driven, and disaster-driven, not management-driven. I have to say, it's so funny.