skip to content

Cutting The Adversary Out

The containment, eradication and recovery arc of NIST SP 800-61, done without telling the intruder they were found and finished only when no path back is left. Interviewers score your trade-off.

on this pageshow

explore

questions

20

What does an EDR's network-isolate action on a compromised host stop, and what does it not stop?

level: juniorimportance: must knowfreq 72%

answer

  1. think about what the button touches
  2. the agent still phones home
  3. one host, not one intruder
  4. damage stopped, access not revoked
  5. persistence and stolen credentials survive it

basics

~20 s

Network isolation cuts a host's traffic except the EDR agent's own channel, so an intruder loses interactive access from that machine. It kills no running process, removes no persistence, revokes no stolen credential, and touches nothing on any other host.

solid answer

~50 s

Isolation is a network control on one machine. The EDR agent drops all inbound and outbound traffic except its own link to the management console, plus whatever the responder explicitly allowlists. That ends the intruder's interactive session from that host and stops it reaching anything else on the network, and it lets you keep working the box through live response. What it does not do is anything about the intruder themselves: processes they started keep running locally, scheduled tasks and services they planted are still there, credentials they harvested still work from anywhere else, and any other host they already own is untouched. Isolation is containment of one host, not eradication of an intrusion — and it is loud, because their session drops the moment you click it. It also freezes your own visibility: whatever they were about to do next, you will not see.

go deeper

for a junior

Be ready to state plainly that isolation is a network control on one machine, that the EDR agent keeps its own channel, and that it removes neither persistence nor stolen credentials.

for a middle

Explain the mechanics: where the filter is applied, why the management channel is exempt, what live response can still do, and why a local process can still cause damage after the cut.

for a senior

Show the judgment around the button — that isolating goes loud, freezes your scoping, and leaves an unfinished eradication phase behind, so you sequence collection and credential work around it rather than treating it as the end.

for a principal

Own the framing that containment scope is a design decision: which assets can be isolated unilaterally, which need an owner's agreement, and what the response plan promises about that before an incident starts.

## What the control actually is "Network isolation" (also called network containment or host quarantine, depending on the EDR vendor) is a command sent to the endpoint agent that installs a local network filter. From that moment the host may talk to essentially one destination — the EDR's own management infrastructure — plus any addresses the responder adds to an allowlist. Everything else, in both directions, is dropped at the host. The carve-out for the agent's channel is the point of the design. It means the machine is cut off from the estate and from the internet while you keep full live-response capability: you can still list processes, pull files, capture a memory image, collect registry hives and run collection scripts over that channel. A responder who thinks isolation ends their access to the box has misunderstood the control. ## What it stops - The intruder's interactive session from that host, immediately. - Outbound command-and-control and any data transfer that has not already completed. - Lateral movement *from* that host to file servers, domain controllers, or anything else reachable on the network. - The host as a launch point. It is a boundary drawn around one machine. ## What it does not stop This is the half candidates skip, and it is where the marks are. - **Local execution.** The machine is still running. A process the intruder started before you isolated keeps executing: it can still encrypt or wipe local data, still clear logs, still delete its own artefacts. Isolation is not a kill switch. - **Persistence.** Scheduled tasks, services, run keys, WMI subscriptions and planted binaries are all still on disk. Containment and eradication are different phases; isolation is squarely the first one. - **Credentials.** Anything they harvested — a password, a Kerberos ticket, a refresh token, an API key, a cloud access key — remains valid and usable from any machine on earth. Cutting the network on the host where the credential was stolen does nothing to the credential. - **Their other footholds.** If they own three hosts and you isolate one, they own two. If their access path is a management agent or a cloud console rather than that specific machine, isolating it removes almost nothing. ## The cost you pay Two costs, and both matter for the isolate-or-watch decision this sits inside. First, **it tells them.** Their session drops with no warning. A capable operator reads that as "detected" and behaves accordingly, which may mean going quiet on the footholds you have not found yet, or moving fast to finish what they came for. Second, **it freezes your understanding.** Everything you know about their objective, their next target and which credentials they are actively using came from watching them work. After isolation you have artefacts — a memory image, a disk, logs — which tell you about the past on one machine. They tell you nothing about where the operator was heading. Scope is the hardest thing to establish in an intrusion, and live activity is the cheapest way to establish it. Third, there is a real user attached to the machine. Somebody's workstation just went dark, mid-task. That is a cost, and on a revenue-bearing system it is a cost somebody else is entitled to argue about. ## Reading it correctly The direction of every claim matters. A quiet host after isolation proves the host cannot reach the network. It does not prove the intrusion is over, does not prove persistence is gone, and does not prove the intruder has lost access to the estate. The absence of further activity from a machine you deliberately silenced is not evidence of anything except that your control worked. So isolation is best understood as: *stop the bleeding from this one wound, buy time, keep your forensic access, accept that you have gone loud and gone blind.* Whether that trade is right depends on how much scope you still do not understand — which is the whole isolate-or-watch argument.

  • After you isolate the host, all the intruder's activity disappears from your telemetry. Why is that not evidence they are gone?
    Because you caused it. The host can no longer reach the network, so of course nothing more appears from it. That says nothing about credentials they already stole, other hosts they already own, or persistence still sitting on the machine. Silence from a source you deliberately muted is not a finding. Proving they are gone needs an estate-wide persistence hunt and a watch for re-entry, not the absence of noise from a quarantined box.
  • What can you still collect from a host once it is network-isolated?
    Everything you could collect before, because the EDR agent's channel is deliberately exempt from the isolation filter. Live response still gives you a process list, network connection table, memory capture, file collection, registry hives and scheduled-task enumeration. Collect volatile state first — memory and current connections — since the host is still running and a live local process can still destroy things.
  • Does isolating the host preserve evidence?
    Partly. It stops remote tampering and stops further exfiltration, which helps. But the machine keeps running: a local process the intruder already started can still delete files, and every minute of uptime overwrites more of the memory and disk state you may want. If the evidence matters, capture volatile state promptly after isolating rather than treating isolation as a pause button.

Isolating a host is like sealing the room the burglar is standing in. They cannot take anything else out, and you can no longer see which door they were reaching for — and the rest of the house still has their copied keys.

saying these in an interview costs you the question

  • Says isolation kills the intruder's processes on the host
  • Believes isolation removes persistence or ends the incident
  • Thinks the analyst loses all access to an isolated host
  • Treats silence after isolation as proof the intrusion is over
  • Assumes stolen credentials stop working once the host is cut off

context

open as a page

Why is deleting the implant from the one server that alerted not eradication?

level: juniorimportance: must knowfreq 68%

basics

~20 s

Because eradication targets the intruder's whole foothold, not one file. They may hold persistence on other hosts, valid credentials taken from yours, and the same unfixed way in. Deleting an implant removes an artefact, not their access.

open as a page

After a confirmed intrusion, why is the most recent good backup usually the wrong restore point?

level: juniorimportance: must knowfreq 70%

basics

~20 s

Because a restore point after an intrusion is chosen against the intrusion timeline, not against data freshness. Any copy written after the intruder got in can contain their accounts, implants and configuration changes, so restoring it restores them.

open as a page

Why does resetting a compromised user's password not end an intruder's access?

level: juniorimportance: must knowfreq 78%

basics

~20 s

A password change only stops future logins that present the old password. Already-issued sessions, access and refresh tokens, Kerberos tickets, application consent grants, app passwords, API keys and intruder-enrolled MFA devices are separate objects that must each be revoked.

open as a page

During a live intrusion, what does tipping off the intruder mean, and how do they typically react?

level: juniorimportance: must knowfreq 68%

basics

~20 s

Tipping off means taking an action the intruder can observe and infer detection from. The three classic reactions are destroying evidence, going dormant on a foothold you have not found, and accelerating exfiltration or turning destructive.

open as a page

On a 300-server Linux fleet with confirmed persistence on nine hosts, which do you rebuild rather than clean?

level: seniorimportance: must knowfreq 58%

basics

~20 s

Rebuild wherever the adversary reached root, where the package manager or kernel could have been touched, or where telemetry cannot account for what they did. Clean in place only where the mechanism is fully enumerated and the host's activity is fully observed — and check what the rebuild pulls from first.

open as a page

After an estate-wide password reset, which identity artefacts still let an intruder back in?

level: seniorimportance: must knowfreq 58%

basics

~20 s

Anything that authenticates without a user password: consented application grants, service-principal secrets and certificates, API keys, static cloud keys and in-flight role sessions, intruder-registered authenticators, and a federation signing key. Enumerate from the intrusion timeline.

open as a page

How do you stage one simultaneous containment cut across three regions against an intruder holding two footholds?

level: seniorimportance: must knowfreq 55%

basics

~20 s

Enumerate every foothold first, then run one written cut list — an owner and a tested step per row — inside a single window on one clock. Pre-position access that survives the cut, and capture evidence before any destructive step.

open as a page

How do you sweep 300 Linux servers for persistence when a third have no EDR agent?

level: middleimportance: should knowfreq 47%

basics

~20 s

Compare every host against its declared configuration and its package database instead of against a sensor. Planted persistence usually surfaces as drift: an added SSH key, an undeclared systemd timer, a new package hook. The gap is unmanaged paths and hosts whose agent stopped reporting.

open as a page

An intruder held domain admin for forty days — how do you decide which backups you can trust?

level: middleimportance: should knowfreq 52%

basics

~20 s

Trust turns on two questions: was the copy written before they got in, and could they have altered or deleted it afterwards. Domain-level privilege reached the backup platform, so offline or immutable copies and its own audit records decide it.

open as a page

Why is the Active Directory krbtgt account password reset twice during eradication?

level: middleimportance: should knowfreq 52%

basics

~20 s

Active Directory keeps the current and the previous krbtgt key, so one reset leaves the old key valid and forged tickets minted with it still work. Reset twice, allowing the first change to replicate to every domain controller in between.

open as a page

Minutes before a planned containment cut, appliance egress spikes and an inbox rule is deleted. What do you conclude?

level: middleimportance: should knowfreq 46%

basics

~20 s

Conclude they know. The flow records prove bytes left to that destination, not what those bytes were, and the rule deletion is a dated act of evidence removal. Cut now, and reopen the scope question.

open as a page

An EDR rule auto-quarantines hosts in a live intrusion you are still scoping. How do you quiet it without going blind?

level: middleimportance: should knowfreq 41%

basics

~20 s

Separate detection from response: leave the rule firing and collecting, and disable only its quarantine action. Disabling the rule itself blinds the case. Time-box the suppression to the planned cut and staff a human for the hits.

open as a page

Before you agree to watch a live intruder instead of isolating the host, what must be written down?

level: seniorimportance: should knowfreq 56%

basics

~20 s

The named behaviours that trigger immediate containment, a time box with a review point, the specific scope questions the watch is meant to answer, the person who authorised it, and who is on the keyboard with the cut pre-staged and rehearsed.

open as a page

After forty days of domain-admin access, do you restore the domain controllers or rebuild the forest?

level: seniorimportance: should knowfreq 44%

basics

~20 s

The decision is about the directory's contents, not the servers. Restore controllers from a pre-compromise system state when you can bound what changed; rebuild the forest when the privileged object graph can no longer be vouched for.

open as a page

A desk head refuses to let you isolate a trading workstation with a live intruder on it. What now?

level: principalimportance: should knowfreq 42%

basics

~20 s

Neither the SOC nor the desk head owns that call alone. Price both outcomes, escalate to the executive accountable for the firm's risk, offer a bounded watch with tripwires or a move to a spare workstation, and record who decided what and when.

open as a page

The platform owner won't rebuild 291 servers you can't prove are clean — how do you declare eradication complete?

level: principalimportance: should knowfreq 39%

basics

~20 s

Stop claiming proof and state criteria instead: what was swept, what could not be, what compensates for the gap, and which named business owner accepts the remainder. Then run a time-boxed re-entry watch with specific tripwires and conditions that reopen the incident.

open as a page

Your mass credential reset covers 4,000 accounts but the helpdesk can re-verify 400 a day. How do you scope it?

level: principalimportance: should knowfreq 38%

basics

~10 s

Rank the population by privilege and evidence of adversary use rather than resetting everyone equally, verify identity out-of-band, apply compensating controls to the un-reset tail, and have a named executive accept the residual exposure.

open as a page

Why is an intruder operating through your licensed RMM agent hard to contain by isolating one host?

level: middleimportance: nice to knowfreq 34%

basics

~20 s

Because the access path is the remote-management tenant, not the machine. The console can open a session on any enrolled host, and blocking the vendor's cloud at the perimeter cuts your own IT operations everywhere at once.

open as a page

Finance rejects the restore point that predates the intrusion — who owns that call and how do you frame it?

level: principalimportance: nice to knowfreq 33%

basics

~20 s

The trade is certain business loss against residual adversary presence, so the accountable business owner takes it, not the responder. Your job is to state honestly what each option costs, offer the middle paths, and record what was accepted.

open as a page