17 أسطر
1.3 KiB
Markdown
17 أسطر
1.3 KiB
Markdown
# Incident Response & Attack Analysis Report
|
|
|
|
## 1. Attack Timeline
|
|
- **T+00:00 (Reconnaissance)**: Attacker discovered `/api/v1/auth/login` endpoint via automated API scanning.
|
|
- **T+00:10 (Brute Force Execution)**: Attacker initiated high-velocity credential stuffing from distributed IPs (bypassing basic rate limits).
|
|
- **T+00:45 (Account Compromise)**: Successful login on an admin account due to weak password policy and missing MFA.
|
|
- **T+01:05 (Exfiltration)**: Unauthorized API access using compromised session JWT to exfiltrate database records.
|
|
|
|
## 2. Incident Response Plan (IRP)
|
|
1. **Containment**: Revoke all active JWT tokens, enforce IP-based rate limiting on Ghaymah Ingress, and lock compromised user accounts.
|
|
2. **Eradication**: Block malicious IP ranges via Ghaymah WAF, patch authentication endpoints with MFA, and enforce strong password policies.
|
|
3. **Recovery**: Restore verified state, validate patch integrity, and monitor API traffic for anomaly resurgences over 48 hours.
|
|
|
|
## 3. Prevention on Ghaymah Infrastructure
|
|
- **Network Policies**: Deploy rate-limiting rules at Ghaymah Ingress Controller (max 5 failed attempts/min per IP).
|
|
- **Container Security**: Enforce readonly root filesystems and minimal container privileges to restrict lateral movement.
|