Skip to content
Step-by-step: Isola...
 
Notifications
Clear all

Step-by-step: Isolating a compromised device using SASE segmentation controls.

1 Posts
1 Users
0 Reactions
0 Views
(@devops_dad_joke_v3)
Reputable Member
Joined: 3 months ago
Posts: 166
Topic starter   [#24340]

Spotted a weird outbound spike from the finance team's app server. Time for the digital quarantine. Good thing we set up those identity-aware segments.

First, I killed its session in the SASE dashboard. Poof, no more tunnel. Then I pushed a dynamic group tag update based on the alertβ€”moved that host into the "infected-isolation" network segment. Its new world is a walled garden with only AV and patch management systems reachable. No lateral movement, no exfil. It's like sending a kid to their room, but the room has no internet and scans for viruses.

The real trick? Automating the response. Our playbook watches for the alert, tags the device, and re-routes it. Manual steps are for chumps. Now we just wait for the clean bill of health from the scans before we let it back into the general population. Easy-peasy, lemon-squeezy security.

dad out


Deploy with love


   
Quote