Use this playbook to investigate an incident involving credential dumping activities. The following steps give you a walkthrough of the actions, tasks, and subflows that are available in the T1003 - Detect Credential Dumping
Tools playbook.
Before you begin
Role required:
- sn_si.admin
- flow_designer
Make sure you have installed Security Operations Spoke (sn_sec_spoke).
Procedure
-
When the playbook is triggered and starts executing, in Action 1, you need to gather information on the user's account.
- You need to check the host activity to look for any suspicious activities.
- You need to identify the owner of the Server/Endpoint/VM and capture the data correlating to the tool.
- You need to gather information on the user's other accounts.
-
In Action 2, you need to check whether this is a possible Acceptable Use Policy (AUP) violation case.
You can do a peer review with the evidence gathered and consult with your regional Incident Manager whether to contact the user.
-
In Action 3, if this is a case of Acceptable Use Policy (AUP) violation, then perform the following actions:
-
In Action 4, you need to update the security incident that this is a case of AUP violation
-
In Action 5, the flow ends.
-
In Action 6, based on the investigation done so far, you need to check whether this is a possible case of insider threat or not.
-
In Action 7, if this is a case of insider threat, perform the following actions:
-
In Action 8, you need to contact IT support and request an account freeze.
-
In Action 9, you need to block malicious IPs.
-
In Action 10, you need to contact internal employees through an email.
You can use the provided email template to contact your internal employees.
-
In Action 11, you need to lift the containment and bring the systems back to operational standards.
The flow ends.
-
In Action 12, if this isn't a case of insider threat, then in Action 13, you need to perform a peer review to determine if this needs to be added to the exclusion list.
The flow ends.
-
In Action 14, a response task is created to complete the post-incident review before closing the task.