Resolve security threats with the playbook
Use the Playbook to resolve certain types of security threats in a step-by-step manner. For example, you can resolve phishing attacks and threats caused by malicious code activity using playbooks.
Before you begin
Role required: sn_si.admin or admin
About this task
As you work through each task, enter work notes to help analyze similar attacks in the future. After a threat is identified, you can also use information in the playbook to quarantine the threat, isolate similarly affected assets, and remove malware.
The base system includes knowledge articles for each of the playbook tasks. You can, however, write your own knowledge articles and associate them to playbook tasks.
Procedure
Resolving user-reported phishing attacks with the playbook
The Phishing playbook guides you through the tasks necessary for analyzing and resolving a phishing attack reported by one of your company's employees.
How security incidents are created from user-reported phishing attacks
During Security Incident Response setup, your system administrator creates a series of email matching rules that can identify emails that contain signs of a phishing attack. When employees receive a suspicious email that contains the common signs of a phishing attack (as defined by your security policies), they can send it as an .EML attachment to the phishing email address defined by your organization.
- The short description includes User Reported Phishing, followed by the actual subject from the originating email.
- The .EML file is attached to the security incident.
- If the .EML contained any observables, they are parsed, and enrichment and threat lookups are automatically performed.
The Phishing playbook contains tasks to help you analyze, contain, and eradicate a phishing threat. The tasks are organized into states (for example, Analysis, Contain, and so forth). When all tasks for a state have been completed, the playbook guides you to the next state.
Analyzing security incident details
- Determining the validity of the incident.
- Studying the impact of the potential threat.
- Coordinating an effective response to the incident.
- Familiarize yourself with the knowledge articles.
- Open the email attachment and examine it for signs of common phishing elements.
- Review threat lookup results.
Containing the security incident
When the security incident is in the Contain state, you are given tasks to review the details of the email. To ensure that threats cannot enter your organization, update your network defenses, in the form of Intrusion Defense System (IDS) and Intrusion Prevention System (IPS) signatures and rules.
- Take actions to limit threat impacts, such as isolating the impacted devices.
- Examine the observables attached to the email.
- Determine whether any email contents are associated with a known threat, including:
- URL
- Email sender
- Phishing URL
- IP address of the sender's SMTP server
Eradicating the malware
After you deploy updated signatures and rules to your antivirus solution, use the tasks in the Eradicate state to determine if malware is present and handle it accordingly.
- Scan the endpoints of affected devices for the presence of malware.
- Remove any malware found.
- As a last resort, wipe and reimage the host devices.
Reviewing the security incident
If you have determined that a phishing attack was a false alarm when performing the Analysis tasks, the security incident moves to the Review state and you need to notify your users so they know it is safe to open the email attachment.
Closing the security incident
When all tasks in the playbook have been completed, the security incident is moved to the Closed state. You must enter closing comments before the incident can be closed.
Cancelling a security incident
When a security incident is in the Review state, and you have successfully informed your users that the email is not a threat, the Cancelled state becomes active and you can cancel the security incident.
Associate a knowledge article with a playbook task
As you analyze security threats using the Security Incident Response playbook, you can view knowledge articles for each task if defined by your organization. If knowledge articles are not present, you can create them and associate them with playbook tasks.
Before you begin
Role required: sn_sir.knowledge_admin, and either sn_si.admin or admin
Procedure
Add a custom task to the playbook
The Security Analyst Workspace base system includes a series of tasks for each threat category. You can create custom tasks that meet the unique needs of your system or customers.
Before you begin
Role required: sn_si.basic or security_admin