Skip to content
Notifications
Clear all

My results after simulating a ransomware outbreak: detection was late but containment worked.

2 Posts
2 Users
0 Reactions
26 Views
(@cloud_ops_learner_99)
Honorable Member
Joined: 4 months ago
Posts: 495
Topic starter   [#19795]

Just tried to simulate a ransomware attack in our dev AWS environment using the Elastic agent on test endpoints. The results were... mixed 😅

The initial file encryption activity wasn't flagged as "ransomware" for over 15 minutes. It was logged, but the critical alert was delayed. However, once Elastic did tag it, the automated containment worked. The infected EC2 instance was automatically isolated from the network using a security group change.

I'm still new to Terraform. Could someone share a basic example of how they'd set up the network isolation security group for this? I want to compare it to what Elastic did automatically.

My security group for containment looked like this:

```hcl
resource "aws_security_group" "containment" {
name = "endpoint-containment"
description = "Isolates compromised endpoints"
vpc_id = aws_vpc.main.id

# Deny all outbound
egress {
from_port = 0
to_port = 0
protocol = "-1"
cidr_blocks = ["0.0.0.0/0"]
action = "deny"
}

# Deny all inbound
ingress {
from_port = 0
to_port = 0
protocol = "-1"
cidr_blocks = ["0.0.0.0/0"]
action = "deny"
}
}
```

The delay in detection has me worried. Has anyone else tested this? Are there specific event thresholds I should tune?



   
Quote
(@data_shipper_joe)
Prominent Member
Joined: 5 months ago
Posts: 680
 

Interesting test, and yeah, that 15-minute detection lag is the scary part, isn't it? The automated containment is great, but the lateral movement damage in that window could be huge.

Your security group looks spot on for isolation. The only thing I'd sometimes add is a small exception for a management CIDR, like allowing SSH from a bastion host IP, just so your incident response team can still get in to investigate if needed. But for a pure, automatic kill-switch, denying everything is exactly right.

For a Terraform example, I've seen teams attach this kind of group dynamically using an AWS Lambda function triggered by the alert. The function would find the instance and swap its security groups. Makes me wonder if Elastic just applied a group like yours, or if it actually modified the existing group's rules.


ship it


   
ReplyQuote