Acronis Advanced EDR Incident Investigation
This document explains how to investigate security incidents using Acronis Advanced EDR, including reviewing alerts, analyzing attack timelines, examining endpoint activity, and investigating common security threats.
Platform: Acronis Cyber Protect Cloud
1. View Security Incidents
Procedure
-
Log in to the Acronis Cyber Protect Cloud console.
Navigate to:
-
Review the list of detected security incidents.
Select an incident to view details such as:
-
Severity level
-
Detection time
-
Affected device
-
Threat category
-
Recommended actions
2. Read the EDR Incident Timeline
Procedure
-
Open the required security incident.
-
Navigate to the Incident Timeline section.
Review the sequence of events:
-
Initial detection
-
Process execution
-
File changes
-
Network activity
-
User activity
-
Remediation actions
-
Use the timeline to understand the attack progression.
3. Analyze the Root Cause of an Attack
Procedure
-
Open the affected incident.
-
Review the attack chain.
Identify:
-
Initial entry point
-
Compromised process
-
User account involved
-
Malicious files or commands
-
Lateral movement activity
-
Review related events to determine the source of the attack.
-
Document findings and remediation actions.
4. Review Process Activity
Procedure
-
Open the affected endpoint.
-
Navigate to process activity.
Review:
-
Running processes
-
Parent-child process relationships
-
Process execution time
-
Command-line arguments
-
Process reputation
-
Identify suspicious or unauthorized processes.
5. Review File Activity
Procedure
-
Open the security incident.
-
Navigate to file activity.
Review:
-
Created files
-
Modified files
-
Deleted files
-
File locations
-
File hashes
-
Identify suspicious files and take appropriate action.
6. Review Network Connections
Procedure
-
Open the affected incident.
-
Navigate to network activity.
Review:
-
Source IP address
-
Destination IP address
-
Ports used
-
Communication timestamps
-
Connected applications
-
Investigate unknown or suspicious connections.
7. Use MITRE ATT&CK Mapping
Procedure
-
Open the security incident.
-
Navigate to the MITRE ATT&CK section.
Review the detected techniques, including:
-
Initial Access
-
Execution
-
Persistence
-
Privilege Escalation
-
Defense Evasion
-
Discovery
-
Impact
-
Use MITRE mappings to understand attacker behavior and improve security controls.
8. Investigate Ransomware Detection
Procedure
-
Open the ransomware-related incident.
Review:
-
Affected files
-
Encryption activity
-
Suspicious processes
-
User accounts involved
-
Verify Active Protection actions.
-
Isolate the affected endpoint if required.
-
Restore affected files from a clean backup.
-
Review the root cause to prevent recurrence.
9. Investigate Malware Detection
Procedure
-
Open the malware alert.
Review:
-
Malware name
-
Detection source
-
File location
-
Process activity
-
Threat severity
Check whether the malware was:
-
Blocked
-
Quarantined
-
Removed
-
Perform additional investigation if required.
10. Investigate Password Spraying Alert
Procedure
-
Open the password spraying incident.
Review:
-
Targeted accounts
-
Source IP addresses
-
Login attempts
-
Authentication failures
-
Identify affected user accounts.
-
Reset compromised credentials if required.
-
Review authentication policies and MFA settings.
11. Investigate Brute-Force Login Alert
Procedure
-
Open the brute-force alert.
Review:
-
Source IP
-
Target account
-
Number of failed attempts
-
Login timestamps
-
Check whether successful access occurred.
-
Block malicious IP addresses if required.
-
Reset affected credentials and review account security.
12. Investigate Suspicious PowerShell Activity
Procedure
-
Open the suspicious PowerShell incident.
Review:
-
PowerShell command executed
-
User account
-
Parent process
-
Execution time
-
Script location
Identify whether the activity is:
-
Authorized administration
-
Malicious execution
Take remediation actions:
-
Stop malicious processes
-
Remove malicious scripts
-
Block affected accounts if required
Related Articles
Acronis Advanced EDR Incident Response Actions
This document explains how to perform incident response actions using Acronis Advanced EDR, including endpoint isolation, threat removal, indicator management, incident closure, and documentation. Platform: Acronis Cyber Protect Cloud 1. Isolate an ...
Acronis Advanced EDR Troubleshooting
This document provides troubleshooting steps for common Acronis Advanced EDR issues, including agent connectivity problems, protection failures, scan issues, false positives, and endpoint performance concerns. Platform: Acronis Cyber Protect Cloud 1. ...
Acronis Advanced EDR Configuration
This document explains how to enable and configure Acronis Advanced Endpoint Detection and Response (EDR), including agent installation, protection plans, malware protection, antivirus scheduling, and security exclusions. Platform: Acronis Cyber ...