Source: Packet Storm Security – News
Author: unknown
URL: https://www.cisa.gov/resources-tools/resources/eviction-strategies-tool
https://www.cisa.gov/resources-tools/resources/eviction-strategies-tool
ONE SENTENCE SUMMARY:
CISA’s Eviction Strategies Tool, featuring Playbook-NG and COUN7ER, aids cyber defenders in crafting customized incident response plans.
MAIN POINTS:
- Playbook-NG and COUN7ER support incident response by providing systematic eviction plans.
- The tool accelerates creation of response plans and offers tailored eviction strategies.
- Users can export their inputs, but cannot alter the tool.
- Playbook-NG uses MITRE ATT&CK® for matching incident findings with countermeasures.
- COUN7ER database offers a collection of post-compromise countermeasures mapped to TTPs.
- COUN7ER entries include intended outcomes, preparation, risks, guidance, and references.
- CISA updates COUN7ER based on threat intelligence and incident observations.
- Playbook-NG allows export in multiple formats like JSON and Microsoft Word.
- Disclaimer emphasizes COUN7ER is informational, with users assuming all risks.
- CISA encourages feedback through an anonymous survey.
TAKEAWAYS:
- Tools are open source under the MIT License to encourage development.
- COUN7ER aligns countermeasures with various security frameworks.
- Playbook-NG provides incident templates for quick customization.
- The tool helps in crisis response and tabletop exercise planning.
- Feedback via an anonymous survey is welcomed by CISA.