Oct. 11, 2023, 5:43 p.m. | Hafiz Muhammad Attaullah

DEV Community dev.to

Incident Response For Common Attack Types



  1. Brute Forcing


Details:

Attacker trying to guess a password by attempting several different passwords

Threat Indicators:

Multiple login failures in a short period of time

Where To Investigate:

• Active directory logs

• Application logs

• Operational system logs

• Contact user

Possible Actions:

If not legit action, disable the account and investigate/block attacker



  1. Botnets


Details:

Attackers are using the victim server to perform DDoS attacks or other malicious activities

Threat Indicators:

• Connection …

action actions active directory application attack attacker brute brute forcing directory incident incident response legit login logs operational password passwords period response system threat types

CyberSOC Technical Lead

@ Integrity360 | Sandyford, Dublin, Ireland

Cyber Security Strategy Consultant

@ Capco | New York City

Cyber Security Senior Consultant

@ Capco | Chicago, IL

Sr. Product Manager

@ MixMode | Remote, US

Corporate Intern - Information Security (Year Round)

@ Associated Bank | US WI Remote

Senior Offensive Security Engineer

@ CoStar Group | US-DC Washington, DC