The ABCs of Containment, Eradication, and Recovery

In the physical realm, a successful hunt ends with either a kill or a capture.  While some might enjoy the thrill of the hunt, no one really wants to walk away empty handed.  Why do we treat hunting in the digital realm differently?  The Containment, Eradication, and Recovery phase of the Incident Response Lifecycle is the digital equivalent of the kill or capture in the physical world.  Proper execution of this phase is necessary for a successful hunt, and it’s as easy as remembering your ABCs.  You’ve stalked and located your prey, evil has been found, are you prepared to take it out? 

I gave this talk at the GoSec 2019 conference in Montreal, the 2019 Texas Cyber Summit in San Antonio, and the 2019 Forensik conference in Montreal. Slides are available below. I’d like to give a shout out to Michael Melone, who I believe originally came up with the “ABCs”, Jared Poeppleman for writing the krbtgt reset script, as well as Andrew Robbins and his team for creating the Bloodhound tool, all of which are referenced in these slides.

If you are interested in having this talk delivered at your event or conference, please contact me through Twitter or LinkedIn.

Leave a Reply

Your email address will not be published. Required fields are marked *