skip to content

Tipping Them Off

A blocked domain, a disabled account or one reimaged host tells the intruder you found them, and the reply is often destruction or a faster push. Interviewers probe the simultaneous cut.

on this pageshow

explore

questions

4

During a live intrusion, what does tipping off the intruder mean, and how do they typically react?

level: juniorimportance: must knowfreq 68%

answer

  1. an opponent, not a fault
  2. everything you do has a visible side
  3. destroy, hide, or hurry
  4. the foothold you did not find
  5. a partial cut is a message

basics

~20 s

Tipping off means taking an action the intruder can observe and infer detection from. The three classic reactions are destroying evidence, going dormant on a foothold you have not found, and accelerating exfiltration or turning destructive.

solid answer

~40 s

Tipping them off is any containment or investigative action whose effect is visible from where the adversary sits, so they conclude they have been found. It matters because an intrusion, unlike an outage, has an opponent who reacts. The three reactions to plan for are destruction (clearing an appliance log buffer, deleting the inbox rule they planted, wiping tooling), dormancy (abandoning the foothold you found and sitting silent on the one you missed, which looks exactly like success), and escalation (compressing weeks of staged collection into minutes of exfiltration, or going destructive). Dormancy is the most dangerous because it produces no signal at all. This is why containment is staged as one cut rather than dribbled out: a partial cut tells them precisely how much you know.

go deeper

for a junior

Be ready to say plainly that a security incident has a live opponent and that your own actions are observable to them. Naming the three reactions — destruction, dormancy, escalation — is the answer being scored.

for a middle

Explain which specific actions are observable and from where: a quarantined endpoint, a killed session, a block on the destination they are using, a query against a device they control. Tie each to the reaction it invites.

for a senior

Show that this drives sequencing: enumerate fully, cut once, and plan the measurement of what left in the final minutes. Be able to say when the tip-off risk is worth accepting because damage is accruing now.

for a principal

Own the framing that dwell time and tip-off risk trade against each other, and that the organisation, not the analyst, decides how much further loss it will tolerate to buy a complete cut.

## An intrusion is not an outage A reliability incident ends when the service is healthy again. A security incident ends only when you can argue the adversary has no path back — and until that argument holds, there is a thinking opponent inside the estate who is watching some of the same systems you are. In many intrusions they are watching from inside your own tooling: the mail platform where your case notes circulate, the edge VPN appliance whose syslog you are reading, the account directory you are querying. Every action you take has an observable side, and 'tipping them off' is the moment your activity becomes visible enough for them to conclude that they have been detected. ## The three reactions **Destruction.** The first instinct of an operator who believes they are burned is to remove what proves they were there. On an edge appliance that means clearing or truncating its own log buffer; in a mail platform it means deleting the inbox rule that was quietly copying a mailbox out. ATT&CK groups this behaviour as Indicator Removal (T1070). Note the direction of the claim carefully: deleting an object does not erase the record of its creation. If the rule-creation event was already exported to your central log store, the deletion is simply a second event on top of the first — and it is a very loud one, because it is dated after your containment planning started. **Dormancy.** The disciplined reaction is not destruction but silence. They stop using the foothold that drew your attention and fall back to the second one you have not found. Nothing burns, nothing is deleted, the alerts stop and the estate looks clean. This is the worst outcome for you because it is unmeasurable: the absence of a detection proves nothing about the estate, and 'we contained it and it went quiet' is exactly what both success and failure look like. A hunt weeks later, or a third-party notification, is often what surfaces it. **Escalation.** If the operator's goal was data and they judge they have minutes rather than weeks, they take everything they staged at once — a burst of egress far above the trickle you had been watching — and may then destroy what they cannot take. Ransomware deployment is the extreme form. This is the reaction that turns a containment plan into a race, and it is the reason you measure what left in the final minutes rather than assuming the cut was clean. A fourth possibility deserves naming: no reaction at all. Plenty of intrusions are run by operators who never notice the defender. You cannot rely on that, but you also should not treat every intrusion as if it were an attentive one. ## Why a partial cut is the classic trigger The canonical tip-off is not a dramatic mistake; it is an incomplete cut. Suppose an adversary has two homes — an implant in the network-edge appliance's own firmware and a dormant inbox rule in the mail platform. If you block the appliance's outbound destination on Monday and leave the mail rule for Tuesday, you have not contained anything; you have sent a message. The block tells them what you found, the surviving rule tells them where to hide, and the gap between the two gives them time to use it. The rule of thumb interviewers want to hear is: enumerate everything first, then cut everything at once. ## What it does not mean It does not mean containment should be postponed indefinitely. The tip-off risk is a reason to sequence and stage the cut, not a reason to leave an adversary in place while damage accumulates. It also does not mean silence about the incident inside your own organisation — that is a separate decision about who is told and over which channel. And some tip-offs are unavoidable: you cannot revoke access without the holder of that access noticing. The craft is in making the unavoidable ones simultaneous and terminal rather than partial and instructive. ## The practical consequences - Keep investigation reads passive where you can; querying a compromised device's management interface is an action on that device. - Do not stage the fix in the system the adversary is living in. - Assume any change with a user-visible effect (a quarantined laptop, a forced password reset, a killed session) is a signal. - Enumerate to the point where you believe you know every foothold, then cut them together at a single planned time. - Plan what you will measure afterwards, because the final minutes before the cut are where escalation shows up.

  • Which of the three reactions is hardest to detect after the fact, and why?
    Dormancy. Destruction and escalation both generate events — deleted objects, cleared buffers, a spike in egress — that you can find later. Dormancy generates nothing: the adversary simply stops. Since the absence of a detection says nothing about whether they are present, you cannot distinguish a successful eradication from a patient one without actively hunting for the second foothold and watching for re-entry.
  • If deleting an inbox rule is a tip-off reaction, why is that deletion still useful to you?
    Because the deletion is itself an audited event, and it is dated. If the creation event was already collected centrally, you retain proof the rule existed, its parameters, and now a timestamp showing when the operator decided to remove it. That timestamp is often the best evidence of when they realised they were seen, which tells you which of your own actions was the tip-off.
  • Does tipping them off ever work in your favour?
    Occasionally, and only deliberately. Provoking a reaction can surface a foothold you had not found — a dormant channel that suddenly activates. But it is a deception operation with a real chance of triggering destruction instead, so it is a planned, authorised choice with monitoring in place, never a side effect of sloppy containment.

Serving an eviction notice on one of two flats a tenant secretly holds: you have not removed them, you have told them which door to stop using.

saying these in an interview costs you the question

  • Treats the incident as an outage with no opponent reacting
  • Says containment should be delayed until everything is understood
  • Assumes the adversary always destroys evidence, never goes quiet
  • Thinks deleting an object erases the record of its creation
  • Reads post-containment silence as proof of eradication

context

open as a page

How do you stage one simultaneous containment cut across three regions against an intruder holding two footholds?

level: seniorimportance: must knowfreq 55%

basics

~20 s

Enumerate every foothold first, then run one written cut list — an owner and a tested step per row — inside a single window on one clock. Pre-position access that survives the cut, and capture evidence before any destructive step.

open as a page

Minutes before a planned containment cut, appliance egress spikes and an inbox rule is deleted. What do you conclude?

level: middleimportance: should knowfreq 46%

basics

~20 s

Conclude they know. The flow records prove bytes left to that destination, not what those bytes were, and the rule deletion is a dated act of evidence removal. Cut now, and reopen the scope question.

open as a page

An EDR rule auto-quarantines hosts in a live intrusion you are still scoping. How do you quiet it without going blind?

level: middleimportance: should knowfreq 41%

basics

~20 s

Separate detection from response: leave the rule firing and collecting, and disable only its quarantine action. Disabling the rule itself blinds the case. Time-box the suppression to the planned cut and staff a human for the hits.

open as a page