ABCDEFGHIJKLMNOPQRSTUVWXYZ
1
4/27/2022START13:57 PST BR3 University Log4J Incident
2
3
ResourceCommand Staff (CS)
4
MattIC = Incident Commander
5
LNO = Liaison Officer
6
KevinS = Scribe
7
Agency Reps (A-Reps) & Technical Problem Solvers
8
TaylorSC = School Contact
9
SonicSME = Subject Matter Expert
10
Elapsed
11
KeyTime
12
Event #(mm:ss)From=>ToKey Event
13
Overview of event: Compromise detected at 13:57 PST. Central Authentication Server (CAS) is the primary authentication service for all customers and is compromised. Customers can't log in and can't perform any basic activities, such as registering for classes, looking at class schedules, making payments, etc.
14
100:00START: Log 4J Incident at BR3 Univ
15
200:21IC=> AllIncident Bridge initiated @1402
16
300:30IC=> AllAssigning Command Staff (CS) positions
17
400:33IC=> AllIC=Matt, LNO=
18
500:38IC=> AllSC=Taylor, SME=Sonic
19
600:50SC=>AllLog4J Attack, CAS, CIO upset
20
700:55SC=>AllKey stakeholders (Administration, Faculty, IT, Security, Dean of Students) contacted.
21
801:58IC=>SMECan you pull Logs? Yes. BE back in 15 Minutes
22
902:11IC=>LNOAdd Security network Log Analysis SME
23
10Can Report #1 to Executive (LNO#1) using key events #1-9
24
1112:44LNO=>ICSecurity Network SME Dev will join bridge
25
1212:45IC=>SMELogs Avail? Yes
26
1312:57IC=>SMEReview logs & rejoin in 30min? Yes
27
1543:18IC=>LNOGet Business Impact in 30 minutes
28
1643:48IC=>LNOSchool impact? No backup service
29
1744:04LNO=>ICBusiness Impact is Major. No secondary option
30
1844:10IC=>SMEUpdate to log review? 10 Minutes
31
2054:30SME=>ICTaking system off line
32
2154:48IC=>SMEETA to take server offline & patch
33
2255:00SME=>IC2 hours. Will back up CAS & forensics logs
34
2355:14IC=>SMETake action report back in 2 hours
35
25 2:05:25CIO=>ICExecutive swoop, CIO upset and wants answers
36
262:05:50IC=>CIOMove into different room w/LNO
37
272:06:08LNO=>CIOSend link to Breakout Room
38
282:06:37LNO=>ICReturn after briefing w/CIO
39
29200 Word Written IMS briefing to SMEs (LNO#2) using key events #1-28
40
302:32:18SME=>ICPatch implemented, CAS & forensics logs retained. System tested, restored and all features are operational.
41
312:33:02IC=>ALLAll CAS services are operational as of 1634 PST. Declaring this incident "Under Control".
42
322:33:27IC=>SMEAll SMEs continue to monitor your environment. Bridge open until all SMEs confirm their environments are stable under load.
43
332:34:11IC=>LNOSend Comms to all stakeholders
44
34Report #3 Incident Resolved, CAN or IMS to Customers (CAN or IMS) (LNO#3)
45
35
46
36
47
38
48
39
49
40
50
41
51
42
52
43
53
44
54
45
55
46
56
47
57
48
58
49
59
50
60
51
61
52
62
53
63
54
64
55
65
56
66
57
67
58
68
59
69
60
70
61
71
62
72
63
73
64
74
65
75
66
76
67
77
68
78
69
79
70
80
71
81
72
82
73
83
74
84
75
85
76
86
77
87
78
88
79
89
80
90
81
91
82
92
83
93
84
94
85
95
86
96
87
97
88
98
89
99
90
100
91