Advanced Persistent Threat (APT) Intrusion Response
Incident response for nation-state / advanced persistent threat (APT) attacks; based on the Mandiant Attack Lifecycle model, SANS FOR508, and Microsoft DART practices.
Preparation
1 steps- APT readiness: threat model and monitoring infrastructure
Identify sector-focused APT groups. Establish correlation rules in SIEM specific to APT TTPs. Retainer agreement with external IR firm. Crown Jewels analysis.
Detection & Analysis
2 steps- Detect APT entry indicators
APT IOCs: authentication at unusual hours, first access to sensitive data stores, known APT C2 traffic, LOLBin usage, web shell. Median dwell time 11 days.
- Build attacker activity map
Full timeline using SIEM + EDR + NDR telemetry. Map Mandiant Attack Lifecycle phases: Reconnaissance, Initial Access, Establish Foothold, Privilege Escalation, Lateral Movement.
Containment, Eradication & Recovery
4 steps- Covert containment — monitoring without leaving traces