Incident Response Lesson 6: Containment and Recovery
Table of Contents
Return to the Detection Engineering and Incident Response Course
Response actions change evidence and business operations. State the purpose, owner, approval, risk, rollback path, and success check before execution.
Choose Action Order
For the course incident, start with this proposed order. The incident commander should decide whether to collect volatile endpoint evidence before isolation when policy permits and ongoing harm is controlled. If exfiltration or active misuse continues, contain first and record what volatile evidence may be lost.
- Preserve cloud audit, endpoint, mail, DNS, and network evidence.
- Isolate
HR-LT-044through the approved endpoint process. - Disable or restrict Morgan’s identity under the incident authority model.
- Revoke active sessions and OAuth grants.
- Remove the malicious mailbox rule after preserving its configuration.
- Collect the document, script, and task definition under policy. Collect remaining volatile evidence where feasible.
- Reset credentials and re-register strong factors through a verified recovery path.
- Rebuild or restore the endpoint from trusted media.
- Validate service, identity, and endpoint health.
- Monitor for recurrence before closure.
Do not execute these steps in a real environment from course notes. Use the organization’s incident plan, legal requirements, and assigned authority.
Write Action Cards
Action: Revoke Morgan's active sessions and application grants
Purpose: Stop continued use of stolen tokens and delegated mail access
Owner: Identity operations
Approval: Incident commander
Evidence first: Export sign-in, consent, application, and session records
Risk: Business interruption and loss of volatile session detail
Rollback: Reauthorize approved applications after review
Success check: Old sessions fail, grant is absent, fresh sign-in uses approved MFA
Write a card for endpoint isolation, mailbox rule removal, credential recovery, endpoint rebuild, and monitoring.
Define Recovery Gates
| Gate | Evidence |
|---|---|
| Identity ready | Password or credential reset, approved factor enrollment, session revocation, consent review |
| Endpoint ready | Trusted rebuild, current patches, security agent healthy, no old task or script |
| Mail ready | Rule review complete, delegated access reviewed, message trace preserved |
| Monitoring ready | Indicators and behavior detections active with owners and expiry dates |
| Business ready | Service owner accepts restored function and residual risk |
Recovery does not end when a device boots. Restoration needs security checks and owner acceptance.
Improve the System
Create work items from observed gaps:
- Block or limit legacy authentication under the identity policy process
- Review application consent and alert on risky delegated scopes
- Collect process parent and command-line fields across managed endpoints
- Monitor scheduled task creation outside approved deployment tools
- Link DNS and endpoint network events by host and time
- Test the Office-to-PowerShell analytic with positive and negative cases
Give each item an owner, due date, evidence target, and validation method. An improvement without a validation step is a proposal.
Practice Steps
- Write five action cards.
- Put the cards in execution order.
- Mark which actions alter evidence.
- Define four recovery gates.
- Write a three-sentence stakeholder update with facts, impact, and next checkpoint.
- Create six improvement work items.
Expected Result: the plan limits access, preserves needed records, restores trusted service, and assigns validation work.
Troubleshooting
| Problem | Fix |
|---|---|
| Containment authority is unclear | Stop at the approval boundary and escalate to the named incident role |
| Identity disablement affects payroll or safety work | Use approved compensating controls and document residual risk |
| Recovery checks fail | Keep the asset out of service and return to the failed gate |
| The incident closes with open unknowns | Record residual uncertainty, owner, review date, and closure rationale |
Verify Your Work
- Every action has an owner and approval path
- The plan records which evidence was preserved before each destructive action and why containment took priority where needed
- Session and OAuth grant response appears beside credential reset
- Recovery gates include identity, endpoint, mail, monitoring, and business checks
- Improvement items carry validation methods
- Stakeholder text separates confirmed facts from open questions
Primary references, checked 2026-10-10: NIST SP 800-61 Rev. 3 and NIST Cybersecurity Framework 2.0 .
Next Steps
Take the Course Quiz , then complete the Capstone .


