Skip to main contentSkip to main content
Room Banner
Back to all walkthroughs
Room Icon

Response and Recovery

Premium room

Understand the Containment, Eradication, and Recovery phase of the Incident Response Lifecycle.

medium

60 min

65

User profile photo.
User profile photo.

To access material, start machines and answer questions login.

The attacker is inside the Nexus Financial environment. The Detection and Analysis phase confirmed the compromise, identified the affected accounts, and mapped the initial attack chain. This room covers Response and Recovery, the phase where the team transitions from understanding the incident to actively resolving it. In SP 800-61r2 terms, this maps to the Containment, Eradication, and Recovery phase.

Learning Objectives

  • Understand Response and Recovery and its place in the SP 800-61r2 framework
  • Learn the difference between containment strategies and when to apply each
  • Understand how ATT&CK maps to attacker behavior and informs containment decisions
  • Understand what eradication and recovery involve in the current Microsoft 365 incident
  • Use to analyze attacker post-compromise activity and identify what needs to be contained and eradicated

Prerequisites

Although this room can be completed as a standalone, it is highly recommended to complete the following rooms before starting this one:

Familiarity with queries is required for the practical tasks. It is also recommended to complete the Microsoft 365 for the module before starting this room.

Module Chain

This module follows a single security incident at Nexus Financial from start to finish across four rooms:

Room What You Do
1 - Preparation Review Nexus Financial's security posture before the attack
2 - Detection and Analysis Detect the incident and analyze it in
3 - Response and Recovery Make containment decisions, confirm the attacker is gone, and identify root causes
4 - Post-Incident Activity Reconstruct the timeline of the attack and revisit what went wrong

Note: This is Room 3 of 4 in the Incident Response module. All four rooms follow the same incident at Nexus Financial.NIST IR Lifecycle with Containment, Eradication, and Recovery highlighted.

Answer the questions below

I am ready to start!