Brute force attack investigation
Responsibility Index Phase Responsibility Identification L1 Analyst:- GSOC Monitoring Team Investigation L2 Analyst:-This includes individuals from Network Team/GSOC Containment L2 Analyst: - This includes individuals from Network Team/ Server team Remediation L2 Analyst:-This includes Network Team/Server Team/GSOC Recovery L2 Analyst:-This includes Network Team/Server Team/GSOC Brute Force attack Procedure Identification Stage Stage Source Identification Brute Force incident is reported by Network Team Incident/If the alert is raised by the SIEM Investigating Stage Stage Actions by Respective Team Investigation Security team checks If the Brute Force attack is identified and an alert generated via SIEM below parameters are considered for investigating: Source addresses of the attempts Firewall Action Investigating Destination on which brute force attem...
Comments