£199.99 £139.99 for one year of Unlimited learning. Offer ends on 14 November 2022 at 23:59 (UTC). T&Cs apply

Find out more
Plan a response
Skip main navigation

Plan a response

.

Organizations shouldn’t attempt to evict an intruder until they have a good working understanding of the topology of the intrusion. Similarly, the method through which an intruder is evicted, and vulnerabilities remediated should be planned rather than executed in an ad hoc manner.

The red team most likely has fallback strategies. A well-planned response counters attacker fallback strategy. A purely reactive response can turn into “whack a mole” where the attacker has a counter move up their sleeve, including becoming stealthier to make it seem as though they have been evicted to the network when what they’ve done in reality is moved laterally to a new compromised host and temporarily ceased activities while they wait out the blue team’s countermeasures.

From an organizational perspective while time is of the essence in terms of evicting the intruder, in most real-world situations the intruder is only detected long after they have infiltrated the network. This means that it’s unlikely that substantively more harm will occur in the time it takes for the blue team to formulate an effective response than would occur if the blue team responded in an immediate and ad hoc manner.

This article is from the free online

Microsoft Future Ready: Fundamentals of Enterprise Security

Created by
FutureLearn - Learning For Life

Our purpose is to transform access to education.

We offer a diverse selection of courses from leading universities and cultural institutions from around the world. These are delivered one step at a time, and are accessible on mobile, tablet and desktop, so you can fit learning around your life.

We believe learning should be an enjoyable, social experience, so our courses offer the opportunity to discuss what you’re learning with others as you go, helping you make fresh discoveries and form new ideas.
You can unlock new opportunities with unlimited access to hundreds of online short courses for a year by subscribing to our Unlimited package. Build your knowledge with top universities and organisations.

Learn more about how FutureLearn is transforming access to education