Acronis Advanced EDR Incident Investigation Guide | Analyze Security Threats

Acronis Advanced EDR Incident Investigation

This document explains how to investigate security incidents using Acronis Advanced EDR, including reviewing alerts, analyzing attack timelines, examining endpoint activity, and investigating common security threats.

Platform: Acronis Cyber Protect Cloud

1. View Security Incidents

Procedure

  1. Log in to the Acronis Cyber Protect Cloud console.
  2. Navigate to:

    Security → Incidents
  3. Review the list of detected security incidents.
  4. Select an incident to view details such as:
    • Severity level
    • Detection time
    • Affected device
    • Threat category
    • Recommended actions

2. Read the EDR Incident Timeline

Procedure

  1. Open the required security incident.
  2. Navigate to the Incident Timeline section.
  3. Review the sequence of events:
    • Initial detection
    • Process execution
    • File changes
    • Network activity
    • User activity
    • Remediation actions
  4. Use the timeline to understand the attack progression.

3. Analyze the Root Cause of an Attack

Procedure

  1. Open the affected incident.
  2. Review the attack chain.
  3. Identify:
    • Initial entry point
    • Compromised process
    • User account involved
    • Malicious files or commands
    • Lateral movement activity
  4. Review related events to determine the source of the attack.
  5. Document findings and remediation actions.

4. Review Process Activity

Procedure

  1. Open the affected endpoint.
  2. Navigate to process activity.
  3. Review:
    • Running processes
    • Parent-child process relationships
    • Process execution time
    • Command-line arguments
    • Process reputation
  4. Identify suspicious or unauthorized processes.

5. Review File Activity

Procedure

  1. Open the security incident.
  2. Navigate to file activity.
  3. Review:
    • Created files
    • Modified files
    • Deleted files
    • File locations
    • File hashes
  4. Identify suspicious files and take appropriate action.

6. Review Network Connections

Procedure

  1. Open the affected incident.
  2. Navigate to network activity.
  3. Review:
    • Source IP address
    • Destination IP address
    • Ports used
    • Communication timestamps
    • Connected applications
  4. Investigate unknown or suspicious connections.

7. Use MITRE ATT&CK Mapping

Procedure

  1. Open the security incident.
  2. Navigate to the MITRE ATT&CK section.
  3. Review the detected techniques, including:
    • Initial Access
    • Execution
    • Persistence
    • Privilege Escalation
    • Defense Evasion
    • Discovery
    • Impact
  4. Use MITRE mappings to understand attacker behavior and improve security controls.

8. Investigate Ransomware Detection

Procedure

  1. Open the ransomware-related incident.
  2. Review:
    • Affected files
    • Encryption activity
    • Suspicious processes
    • User accounts involved
  3. Verify Active Protection actions.
  4. Isolate the affected endpoint if required.
  5. Restore affected files from a clean backup.
  6. Review the root cause to prevent recurrence.

9. Investigate Malware Detection

Procedure

  1. Open the malware alert.
  2. Review:
    • Malware name
    • Detection source
    • File location
    • Process activity
    • Threat severity
  3. Check whether the malware was:
    • Blocked
    • Quarantined
    • Removed
  4. Perform additional investigation if required.

10. Investigate Password Spraying Alert

Procedure

  1. Open the password spraying incident.
  2. Review:
    • Targeted accounts
    • Source IP addresses
    • Login attempts
    • Authentication failures
  3. Identify affected user accounts.
  4. Reset compromised credentials if required.
  5. Review authentication policies and MFA settings.

11. Investigate Brute-Force Login Alert

Procedure

  1. Open the brute-force alert.
  2. Review:
    • Source IP
    • Target account
    • Number of failed attempts
    • Login timestamps
  3. Check whether successful access occurred.
  4. Block malicious IP addresses if required.
  5. Reset affected credentials and review account security.

12. Investigate Suspicious PowerShell Activity

Procedure

  1. Open the suspicious PowerShell incident.
  2. Review:
    • PowerShell command executed
    • User account
    • Parent process
    • Execution time
    • Script location
  3. Identify whether the activity is:
    • Authorized administration
    • Malicious execution
  4. Take remediation actions:
    • Stop malicious processes
    • Remove malicious scripts
    • Block affected accounts if required
    • Related Articles

    • Acronis Advanced EDR Incident Response Actions

      This document explains how to perform incident response actions using Acronis Advanced EDR, including endpoint isolation, threat removal, indicator management, incident closure, and documentation. Platform: Acronis Cyber Protect Cloud 1. Isolate an ...
    • Acronis Advanced EDR Troubleshooting

      This document provides troubleshooting steps for common Acronis Advanced EDR issues, including agent connectivity problems, protection failures, scan issues, false positives, and endpoint performance concerns. Platform: Acronis Cyber Protect Cloud 1. ...
    • Acronis Advanced EDR Configuration

      This document explains how to enable and configure Acronis Advanced Endpoint Detection and Response (EDR), including agent installation, protection plans, malware protection, antivirus scheduling, and security exclusions. Platform: Acronis Cyber ...