containing-active-breach

Solid

Executes containment strategies to stop active adversary operations and prevent lateral movement during a confirmed security breach. Implements short-term and long-term containment using network segmentation, endpoint isolation, credential revocation, and access control modifications. Activates for requests involving breach containment, lateral movement prevention, network isolation, active threat containment, or live incident response.

AI & Automation 38 stars 5 forks Updated yesterday MIT

Install

View on GitHub

Quality Score: 89/100

Stars 20%
53
Recency 20%
100
Frontmatter 20%
70
Documentation 15%
100
Issue Health 10%
80
License 10%
100
Description 5%
100

Skill Content

# Containing Active Breaches ## When to Use - A confirmed intrusion is in progress with an active adversary on the network - Malware is spreading laterally across endpoints or servers - A compromised account is being used for unauthorized access to systems - Ransomware encryption has been detected and is actively propagating - An attacker has established command-and-control communications from internal hosts **Do not use** for post-incident cleanup when the adversary is no longer active; use eradication procedures instead. ## Prerequisites - Confirmed incident classification with P1 or P2 severity from triage - EDR console access with host isolation capabilities (CrowdStrike Falcon, Microsoft Defender for Endpoint, SentinelOne) - Network firewall and switch management access for segmentation - Active Directory or identity provider administrative access for credential actions - Pre-approved containment authority documented in the incident response plan - Evidence preservation plan to avoid destroying forensic artifacts during containment ## Workflow ### Step 1: Assess Containment Scope Before taking containment actions, map the full scope of compromise to avoid partial containment that alerts the adversary: - Identify all confirmed compromised hosts via EDR telemetry and SIEM correlation - Map lateral movement paths using authentication logs (Windows Event ID 4624 Type 3 and Type 10) - Identify all compromised credentials (check for pass-the-hash, Kerberoasting, DCSyn...

Details

Author
adriannoes
Repository
adriannoes/awesome-vibe-coding
Created
8 months ago
Last Updated
yesterday
Language
Jupyter Notebook
License
MIT

Similar Skills

Semantically similar based on skill content — not just same category