How to Handle a Cyber Attack: The Complete PICERL Incident Response Guide
HELLO FRIENDS
WLCOME TO MY CYPHER LOG
INCIDENT RESPONSE LIFECYCLE
Hello guys, today I came up with the most important topic which is the Incident response life cycle, actually we have already seen the overview in our past blog which is incident response forensic basics,
And today we are going to deep dive into that.
And there is one more day to finish the fundamentals of cyber security, then I would like to start linux and get into the technical side to strengthen my cyber career if you're also interested in that you can follow that too. I hope we can achieve more in our career.
LET'S GET INTO THE TOPIC
INCIDENT RESPONCE LIFECYCLE
The Incident response lifecycle is nothing but the playbook of how investigators would and must handle a crime during and after the period. It has 6 phases of handling an incident. So let's see what are the 6 phases and how investigators follow the 6 phases.
THE 6 PHASES OF PICERL
Don't overthink about the term PICERL, actually that looks fancy but that's just simple terms which are.
P - PREPARATION
I - IDENTIFICATION
C - CONTAINMENT
E - ERADICATION
R - RECOVERY
L - LESSON LEARNED
let's see what they will do in the 6 phases of PICERL
PREPARATION
Preparation is the first phase of this cycle. There is a saying which is "Prevention is better than cure". That is the main concept of Preparation, because in this modern era we don't know how, when and who will do the attack. So all we need to do is be prepared before it happens, whatever will happen but being prepared is this crucial step we need to do.
Now you will have a question, being prepared is ok but how can I be prepared to clear that,
Take an example to be more clear,
If you're the cyber security analyst in a company and all you need to do is always keep the company's data secured no matter what. So now all you need to do is set up things like, SIEM tools and we have already seen about SIEM tools in our blog you can check that to know more about that, preparing forensic kit, and training the team to be prepared for an attack and you need to focus on general employee of the company whom the attacker will Target using social engineering or they can trapped by accident, so as a cyber security analyst of your company you need to give an awareness to your company employees to be aware of cyber threats...
That's how you can be prepared for an attack and to prevent an attack before it happens.
IDENTIFICATION
Identification is finding an incident that has actually occurred and figuring out its scope.
As an employee you already prepared for everything and a cyber incident happened in your company now you need to find the answer for, what happened?, when did it start?, and what are the damages occurred.
But how will you find you find it?.
First you need to check the SIEM alerts, antivirus logs and review the reports so that you can get the overview of the incident and also the answer for your questions.
CONTAINMENT
Now, you find out the incident and the next step you need to do is limit the damage and prevent the attack from spreading all over the systems of your company.
First don't panic about the attack, if you panic there is a possibility of spreading the attack. So be patient and disconnect the infected machine from other systems but never power off the system this can destroy the RAM data and you may lose all your volatile data. You can disconnect it by pulling the Ethernet cable and disabling Wi - fi. And be careful about not destroying the evidence during containment.
ERADICATION
The next phase is eradication, now you need to remove the presence of the attacker and the attack occurred, like deleting malware, search for the vulnerability which is exploited and patch it, resetting passwords and reimaging hard drives. But there is another one you need to remember which is never to do the eradication before you have forensically imaged the evidence. If you have done it before, you may tend to lose the evidence.
RECOVERY
Recovery is like doing things after a big disaster like you need to do everything to make the situation normal like before. As a cyber security analyst you already have the backup of everything so you can restoring everything again from the clean backup and back to the normal operations. And monitor every activity so you can prevent another attack.
LESSON LEARNED
This is the last and most important phase which is lesson learned as a cyber security analyst you need to map every inch of the incident like how it happens, when it happens, who did that and what are the ways they used, tactics, techniques. So that you can be aware of the incident and prevent it from happening again. By this you can identify if there is more vulnerability in your overall systems and you can be more aware of things before it happens.
So that's it guys this is the whole lifecycle of incident response, I hope you guys understood it well if there is any doubt you can let me know in comments. Happy learning and we can learn more things in our blog so you better stay tuned with our blog.

Comments
Post a Comment