Skip to main content
INCIDENT-RESPONSE-IT5 MIN READ

Work through a containment plan without blowing away scope

Build a containment plan that sequences host, identity, and network actions around investigative value.

A suspected lateral-movement event touches one jump box, one service account, and two Linux hosts. The team wants a containment plan that is fast but not blind. For each action: risk reduced -> evidence preserved/lost -> next decision enabled The shortcut is to list every disruptive action at once: disable all accounts, reboot everything, block whole network segments, and hope the blast radius shrinks faster than the evidence. Step 1 Action: isolate the jump box from the network Risk reduced: stops new interactive use from that host Evidence impact: preserves memory and process state Start with the host most likely…

Read the full lesson

Sign up free — one personalized lesson every day, matched to your role and goals.

Already have an account? Sign in

← Back to library
Contact us