Emergency Incident Response
Welcome to the MANDIANT Incident Response (IR) Emergency web page. If you need immediate assistance for a possible incident please contact us at help@mandiant.com and/or at 1.877.962.6342.
Computer security incidents are complex, stressful, and not often part of your routine business operations. Therefore, you will want to consider the following activities to ensure you can start on the path to resolving the incident in an appropriate manner.
Initial Incident Response Activities
- Assign one person to have overall responsibility to resolve the incident.
- Enact your Incident Response plan if you have one.
- Assemble the Incident Response team.
- Define the objectives and goal of the response.
- Develop a communication strategy for internal & external contacts.
- Gather all technical tools to be used during the response.
- Collect and review all the information that is currently at your disposal (See Initial Data Collection Below).
- Match your response against any reporting/compliance requirements you may have.
- Implement network and host-based countermeasures to assess the scope of the incident.
- Involve legal counsel and/or law enforcement as deemed necessary.
Initial Data Collection
- Obtain and/or develop a network topology
- Collect and review relevant log files
- DNS logs
- DHCP logs
- VPN concentrator logs
- Web application firewall logs
- Proxy logs
- Intrusion detection/prevention system(s) logs
- Firewall logs
- Windows event logs
- Netflow data from routers and switches
- Anti-virus logs
- Host-based intrusion prevention (HIPs) logs
- Obtain live response data
- Perform forensic preservation of the relevant systems (if needed)
- Collect and analyze identified malware