Triaging an Incident
Well it finally happened—we may have been breached. Our Cyber First Responder left the attached PCAP from her initial response actions, but then had to leave for the East coast on a higher priority response. The CISO declared an “incident” and now wants you to investigate the PCAP of what we believe to be an attack. Is it an attack or something else? So now it is up to you, our new Security Analyst I, to complete the response actions. You get the analysis correct and you get a bonus and early promotion to Security Analyst II.
GRADING: The grade will come from your paper, and supporting documentation. Papers which are clearly organized, referenced, describe the sequence of events and subsequent analysis, and provide sound conclusions based on the presented analysis/evidence will be graded higher. The more malicious activity you find and the remediation recommendations you make will score high. Finally, we need to know—is this a real attack? Grades will reflect “more right” versus “more wrong” levels of effort. A soft copy is due NLT than end of day on the Blackboard due date.