Respond and rebuild

Contain the host

Limit attacker access and outgoing harm using provider controls, credential revocation, isolation, and carefully recorded actions.

8 minute lesson

~~~

Containment protects other systems and users. Do it deliberately so you do not lose the only evidence or recovery path.

Isolate the host from public traffic or detach it behind provider controls, revoke affected keys and tokens, and block known malicious paths. Snapshot where policy allows and keep an action timeline. Do not trust the compromised host to prove it is clean.

Disconnecting the VPS stops public abuse but may also cut off volatile evidence and customer traffic. Provider firewall controls can isolate it without trusting commands run inside the suspect host.

Decide which evidence is time-sensitive before powering down. Memory and active connections disappear, while continued operation may allow more harm, so the incident lead must choose deliberately.

Write and rehearse the containment order using a disposable VPS and provider-side controls. Prove public traffic stops, affected credentials fail from another machine, and the action timeline and evidence copy remain available.

Lesson completed

Take this course offline

Get every free book and course as PDF and EPUB files.

Get the download library →