{ "model": "soc", "state": { "organisation": "Kestrel Stores, a retail organisation. This alert queue receives endpoint alerts on suspicious files.", "playbook": "Kestrel Stores endpoint alert card. Covers suspicious files found on company computers. Use it for every new alert from the endpoint protection agents.\nDefinitions: The file reputation service returns one of: malicious (with the malware family), known good, unknown (the file has not been rated yet), or lookup failed. A file that ran was executed on the computer; otherwise it was only written to disk.\nAsset inventory (host, role, criticality): BKP-40 (backup server, critical); MTG-PC-34 (meeting-room computer, important); ERP-DB-19 (ERP database server, critical); PKI-04 (certificate authority server, important); DEV-WS-35 (developer workstation, standard); TEST-WEB-29 (test web server, standard); CRM-38 (CRM server, important); EXEC-LT-05 (executive laptop, important); INTRA-31 (intranet web server, important); HR-APP-37 (HR application server, important).\nSuspicious traits: A file is suspicious if it has no digital signature. Also if a section has entropy above 7.18. Also if it imports any of these: AdjustTokenPrivileges, CryptAcquireContextA, CryptEncrypt, InternetOpenUrlW, SetWindowsHookExW, URLDownloadToFileA, WinExec. Also if it imports no functions at all.\nRules in order, first match decides:\n(1) Unknown hosts: if the host is not in the asset inventory, escalate the alert.\n(2) Malicious files. Reputation is malicious? Check the family. Family is delf, downloadguide, high, kovter, vittalia or zamg? Escalate. File ran? Isolate the host. File did not run? Block the file. Critical hosts are never isolated automatically. Rule says isolate a critical host? Escalate instead.\n(3) Failed lookups: if the reputation lookup failed, escalate when the host is critical. Otherwise investigate.\n(4) Unknown files: reputation unknown. Count the suspicious traits. With 2 or more traits, block the file if it did not run. If it ran, investigate. With fewer traits, investigate when the host is critical. Otherwise ignore the alert.\n(5) Known good files: reputation known good. Ignore the alert.\nActions: This team may ignore, investigate, isolate, block or escalate alerts. If a rule calls for an action that is not allowed here, escalate instead.", "alert": "Sunday 14:48 EDR ALERT host=CRM-38 user=f.jensen file=\"D:\\Shared\\Apps\\invoice_viewer.exe\" sha256=53eb6d2d440384ac885525f1af04c3688f7080a5f034e54325bfbeea21922e7b size=139264 first_seen=2018-11 execution=\"ran\" signed=no sections=\".text 5.80, .rdata 5.02, .data 3.98, .rsrc 7.43\" imports_total=54 notable_imports=\"none of note\" urls=0 reputation=\"malicious (family zbot)\"" }, "questions": { "action": { "type": "choice", "instructions": "You are the first-line analyst in a security operations centre. Apply the organisation's playbook to the new alert and choose the action the playbook requires. The playbook's rules are checked in order and the first rule that matches decides.", "criteria": { "isolate": "Isolate: cut the affected internal computer off the network.", "investigate": "Investigate: open a case for an analyst; no containment now.", "escalate": "Escalate: hand the alert at once to the senior responder.", "ignore": "Ignore: close the alert because no action at all is needed.", "block": "Block: block the outside address, file or account involved." } } } }