Run TableTop exercises & simulations

Run Tabletop Exercises

Use table-top exercises and other security simulations to train the blue team, and to verify that they are preapred to respond to security incidents according to the corporate guildelines.

These experiential learning are crucial to build confidence and agility in the team (“learning by doing”)

Before your tabletop

  1. You should make sure you have people trained on basic incident response procedures (such as gathering evidence taking a snapshot, disabling IAM users, isolating EC2 instances, etc)
  2. You should have crear definitions on priorities (gather information vs restoring operations)
  3. Prepare tooling for Incident Response

Your exercise should include

  1. Gather the incident response team into the “war room” (isolated meeting room)
  2. Meeting compliance or contractual obligations regarding communications
  3. Communications plan with clear escalation path and times
  4. The facilitator should describe the scenario
  5. The incident responders (blue team) explain how they would act (ideally showing the actions they would take to validate their skill)
  6. The facilitator continues narrating what happened next iterating with the blue team’s actions
  7. The facilitator describes the end result with potential issues not found / threats not erradicated
  8. Learn from the mistakes during the execise, work towards the incremental improvement

The reality will likely vary from the playbook as is, so you have to be prepared to adapt to rare and unexpected situations, such as evation techniques and anti-forensics (such as altering the integration with the SIEM solutions so that activity in certain regions is not reported)

How to run effective security incident response simulations?

View re:Inforce Session: Running effective security incident response simulations

Hands-on Gamified simulations

AWS offers a platform to simulate real-world scenarios that include security challenges for the blue team to respond, in a risk-free environment, as it’s on temporary AWS accounts provided by the platform.

Your teams can compete (Jam event) or you can learn individually (Jam journey) resolving the challenges by yourself (similar to a “capture the flag” challenge but for the defenders), you start from a bad situation such as “you received an abuse notification”

Participants will have to identify and remediate misconfigurations, compromised iam credentials, vulnerabilities, and restoring operatios, validating their skills in a controlled environment.

Learn more about AWS Jams here Access AWS Jams challenges here: AWS Jams with Security challenges

AWS Jams with Security challenges are available on the paid version of Skillbuilder or can be delivered as part of an AWS Training & Certification Course

AWS CloudSaga

If you have a skilled team that wants to simulate in your own sandbox environment (NOT in production!!), you can use AWS CloudSaga , a tool that runs in command line to simulate security events.

AWS CloudSaga is for customers who want to test their environment against documented security events from the AWS CIRT. Using AWS CloudSaga, simple scenarios that mimic actual security events can be run against a customer’s environment, testing the customer’s response plans and defenses when these events occur, and improve defenses of their AWS environment from the results.

Who can help you with the task

1) AWS Professional Services - Security Incident Response Simulations (SIRS)

AWS Offers a standardized service to help you in this task:

AWS Security Incident Response Simulation (SIRS) is designed to help customers validate, test, and confirm their security processes, roles, responsibilities, communication paths, security controls, and security response mechanisms. This is achieved using the SIRS Tabletop offering.

SIRS is also designed to validate roles, responsibilities, and communication paths across the organization and can be aimed at both technical and security teams as well as C-Level executives and business stakeholders.

The format used is a narrative-driven scenario where each participant plays their actual role in the company. Customers can choose from a number of different scenarios or build custom scenarios to validate and test their security controls in the AWS Cloud. The engagement is typically delivered as a series of meetings to prepare the scenario and a 2-day engagement simulating scenarios and providing feedback to improve your Incident Response Playbooks.

Please contact your AWS account team directly or request direct contact with AWS Professional Services

2) AWS Consulting Partner

AWS Partners can help you plan and execute your incident response Tabletop, go to AWS Partners for security incident response to find partners such as Deloitte, Accenture, Atos, etc.

Additional info: AWS Security Incident Response Guide

Access the complete AWS Security Incident Response whitepaper here