Oct. 11, 2023, 5:43 p.m. | Hafiz Muhammad Attaullah

DEV Community dev.to

Incident Response For Common Attack Types



  1. Brute Forcing


Details:

Attacker trying to guess a password by attempting several different passwords

Threat Indicators:

Multiple login failures in a short period of time

Where To Investigate:

• Active directory logs

• Application logs

• Operational system logs

• Contact user

Possible Actions:

If not legit action, disable the account and investigate/block attacker



  1. Botnets


Details:

Attackers are using the victim server to perform DDoS attacks or other malicious activities

Threat Indicators:

• Connection …

action actions active directory application attack attacker brute brute forcing directory incident incident response legit login logs operational password passwords period response system threat types

SOC 2 Manager, Audit and Certification

@ Deloitte | US and CA Multiple Locations

Network Security Engineer

@ Meta | Menlo Park, CA | Remote, US

Security Engineer, Investigations - i3

@ Meta | Washington, DC

Threat Investigator- Security Analyst

@ Meta | Menlo Park, CA | Seattle, WA | Washington, DC

Security Operations Engineer II

@ Microsoft | Redmond, Washington, United States

Engineering -- Tech Risk -- Global Cyber Defense & Intelligence -- Bug Bounty -- Associate -- Dallas

@ Goldman Sachs | Dallas, Texas, United States