Automating the Compromised Credential Playbook
ID: 7639b71d-b665-5bc3-a752-9d43dbf36fbc
STIX ID: report--7639b71d-b665-5bc3-a752-9d43dbf36fbc
Feed Name: ReliaQuest Blog
This blog post describes practical automation techniques for handling compromised credentials across three phases—containment, investigation, and remediation—providing recommended automated actions (quarantine/delete phishing emails, block domains/IPs, terminate sessions and force password resets, isolate/un-isolate hosts) and configuration considerations to reduce false positives and collateral impact.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
