Work through a containment plan without blowing away scope
Build a containment plan that sequences host, identity, and network actions around investigative value.
A suspected lateral-movement event touches one jump box, one service account, and two Linux hosts. The team wants a containment plan that is fast but not blind. For each action: risk reduced -> evidence preserved/lost -> next decision enabled The shortcut is to list every disruptive action at once: disable all accounts, reboot everything, block whole network segments, and hope the blast radius shrinks faster than the evidence. Step 1 Action: isolate the jump box from the network Risk reduced: stops new interactive use from that host Evidence impact: preserves memory and process state Start with the host most likely…
Sign up free — one personalized lesson every day, matched to your role and goals.
Already have an account? Sign in