Submit complete Ghaymah SecOps exam solution
هذا الالتزام موجود في:
16
q2-incident-response/incident-report.md
Normal file
16
q2-incident-response/incident-report.md
Normal file
@@ -0,0 +1,16 @@
|
||||
# Incident Response & Attack Analysis Report
|
||||
|
||||
## 1. Attack Timeline
|
||||
- **T+00:00 (Reconnaissance)**: Attacker discovered `/api/v1/auth/login` endpoint via automated API scanning.
|
||||
- **T+00:10 (Brute Force Execution)**: Attacker initiated high-velocity credential stuffing from distributed IPs (bypassing basic rate limits).
|
||||
- **T+00:45 (Account Compromise)**: Successful login on an admin account due to weak password policy and missing MFA.
|
||||
- **T+01:05 (Exfiltration)**: Unauthorized API access using compromised session JWT to exfiltrate database records.
|
||||
|
||||
## 2. Incident Response Plan (IRP)
|
||||
1. **Containment**: Revoke all active JWT tokens, enforce IP-based rate limiting on Ghaymah Ingress, and lock compromised user accounts.
|
||||
2. **Eradication**: Block malicious IP ranges via Ghaymah WAF, patch authentication endpoints with MFA, and enforce strong password policies.
|
||||
3. **Recovery**: Restore verified state, validate patch integrity, and monitor API traffic for anomaly resurgences over 48 hours.
|
||||
|
||||
## 3. Prevention on Ghaymah Infrastructure
|
||||
- **Network Policies**: Deploy rate-limiting rules at Ghaymah Ingress Controller (max 5 failed attempts/min per IP).
|
||||
- **Container Security**: Enforce readonly root filesystems and minimal container privileges to restrict lateral movement.
|
||||
المرجع في مشكلة جديدة
حظر مستخدم