skip to content

Declaring an Intrusion

Someone with authority names the activity adversarial, grades it by what the intruder reached, and pulls in counsel — identification in NIST 800-61 and PICERL terms. Interviewers open scenarios here.

on this pageshow

explore

questions

24

What is 'patient zero' in an intrusion, and why is the alerting host rarely it?

level: juniorimportance: must knowfreq 72%

answer

  1. first controlled, not first noticed
  2. detections fire on later, noisier stages
  3. work backwards and forwards from the alert
  4. can be an account, not a machine
  5. earliest observed is not earliest actual

basics

~20 s

Patient zero is the first asset in your estate the intruder actually controlled. The host that alerted is only where a rule happened to fire, usually later in the chain, once the intruder moved and grew noisier.

solid answer

~40 s

Patient zero is the first host, account or credential the intruder controlled inside your boundary; the alerting host is simply where a detection fired. Detections mostly cover post-exploitation behaviour, while initial access often looks like a normal authenticated session, so the first alert is typically several steps downstream. A concrete shape: an alert fires on a CI runner spawning an unexpected child process, and working backwards shows the entry was a VPN session days earlier authenticated with a client certificate lifted from a contractor laptop. The runner is where you noticed; the certificate and the laptop are where it started. Until you have identified the entry point you cannot bound credential-reset scope or argue that eradication closed the way back in.

go deeper

for a junior

Be ready to define patient zero in one sentence and say plainly why the host that alerted is usually not it. Knowing that it can be an account rather than a machine already puts you ahead.

for a middle

Explain the mechanism: detections cover post-exploitation behaviour, while initial access often arrives as a normal authenticated session that no rule fires on.

for a senior

Show that you work an investigation in both directions from the alert, and connect the entry point to concrete containment, eradication and credential-reset scope.

for a principal

Own what the organisation asserts when the entry point is never established, and insist that reports separate observed activity from inferred activity.

## What the term means **Patient zero** is the first asset in your estate that the intruder actually controlled: the start of the chain of compromise, not the start of your investigation. The epidemiology metaphor holds in exactly the part that matters. The case that gets noticed first is usually a downstream case, and finding the index case is separate work with its own evidence. 'Asset' is deliberately broad here: - a **host** — a laptop, a server, a build runner; - an **account or credential** — a service account, a client certificate, an API token. If the first thing the intruder controlled was a credential used from their own infrastructure, no machine of yours is patient zero and the identity is; - **something you do not own**, such as a contractor's laptop. Then the useful internal statement becomes *what did they first reach inside our boundary*, recorded alongside the external origin so the two are not conflated. ## Why the alerting host is usually not it Detections are written against behaviour that is both observable and unusual: an odd parent-child process pair, credential access, an unexpected outbound connection, an anomalous administrative action. Nearly all of that is **post-exploitation** behaviour. Initial access frequently looks like a well-formed authenticated session — a VPN session established with a valid client certificate, a token used from a plausible network, a build job started by a service account that starts build jobs every day. Nothing in those records is anomalous on its face, so no rule fires, and the first alert arrives only once the intruder does something a rule was written for. The practical consequence: the alerting host tells you where a rule fired. It carries no information about ordering. Treating it as the start of the intrusion is the single most common scoping error in this work, because everything downstream — reset scope, eradication list, what you tell anyone — inherits that wrong anchor. ## Two directions from the alert From the alerting entity you work in both directions at once: - **Backwards**, toward first foothold: how did this account or host come to be under adversary control, and from where? Each answer produces a new entity and a new earlier date, until you reach either the entry point or the edge of your evidence. - **Forwards**, toward spread: every host, account, credential and system this entity touched while under control, each with a date. The output is one dated picture, not a narrative: per entity, the earliest and latest observed adversarial activity, how it was reached, what it reached next, and the record that proves each cell. ## Getting the direction of each claim right Records support narrower claims than people read into them. A successful VPN authentication proves a **credential was accepted** by the concentrator, not that the named contractor was present or that their laptop was healthy. A build job log proves a **job ran** and what its steps emitted, not that the engineer named on the commit triggered it. An EDR alert proves a **detection fired**, not that something malicious happened. Patient zero is an assertion built from those narrow claims, so it is only as strong as the weakest link you did not qualify. Equally: **earliest observed** is not **earliest actual**. Your evidence gives an upper bound on when the intrusion started. It gives no lower bound at all unless you can argue coverage — that a source capable of showing earlier activity existed, was healthy and was searched. ## Why it matters operationally Three things hang off identifying the entry point: 1. **Eradication.** The entry path is what re-admits them. Remove implants on the hosts you know about and leave the accepted certificate valid, and you have cleaned up after an intruder who can walk back in the same way. 2. **Credential and secret scope.** Whatever was readable at the foothold — tokens on that laptop, secrets a build job could read — is the reset list. Anchoring on the wrong first asset gives you the wrong list. 3. **What you can say.** The start date shapes every statement made about the intrusion, and it is the claim most likely to be tested later. ## When it is never established Sometimes it is not found. Telemetry did not exist at the entry point, or existed and has aged out. That is a legitimate result, and the honest report says *earliest activity attributed to this intrusion is X, initial access is not established, and here is why* — rather than promoting the earliest thing you happened to see into a start date it cannot carry.

  • Can patient zero be an identity rather than a host?
    Yes. If the first thing the intruder controlled was a service account, a client certificate or an API token used from their own infrastructure, then no machine of yours is patient zero. You record the identity as the index case, the first internal asset it reached, and the external origin separately, so nobody later reads the first host as the entry point.
  • Why bother finding the entry point if you have already contained every host you know about?
    Because the entry path is what re-admits them, and the secrets readable at the foothold set your reset scope. Containment on known hosts stops current damage; it does not revoke an accepted certificate, a refresh token or a service-account key that was taken earlier. Eradication that skips the entry point invites re-entry through the same door.
  • The earliest thing you can see is lateral movement, not initial access. What do you write down?
    Write the earliest observed activity with its date and the record that shows it, and state explicitly that initial access is not established, with the reason: no telemetry covered that surface, or the window has aged out, or it has not yet been found. Keep the two as separate claims so neither is read as the other.

saying these in an interview costs you the question

  • Says the first alert marks the start of the intrusion
  • Assumes patient zero is always a workstation, never an account
  • Reads a successful authentication as proof the named user was present
  • Calls eradication complete without identifying the entry path
  • Uses earliest evidence and earliest compromise interchangeably

context

open as a page

Why does a ransomware playbook pre-decide the ransom position and who may disconnect?

level: juniorimportance: must knowfreq 68%

basics

~20 s

Because the extortion note arrives with a countdown, and the decisions it forces — pay or refuse, disconnect or keep producing, call the insurer and counsel — belong to executives who are asleep. Pre-deciding removes hours of paralysis.

open as a page

A compromised read-only auditor account could query a regulated customer table — what must you establish before grading that as data exposure?

level: juniorimportance: must knowfreq 74%

basics

~20 s

Entitlement is not access. The account's grants tell you what was reachable; only the warehouse's query-audit records tell you which tables and columns were actually read. Grade the reach now, call it exposure only where query evidence supports it.

open as a page

When an intrusion is declared, which functions beyond the security team join, and what does each decide?

level: juniorimportance: must knowfreq 58%

basics

~20 s

A declared intrusion adds legal counsel, privacy, HR when the subject is an employee, communications, an executive who can authorise disruptive action, and often a forensic firm retained through counsel. Security keeps the facts; they own the decisions.

open as a page

A CERT's intrusion tip finds no support in your surviving logs — can you close it as unfounded?

level: middleimportance: must knowfreq 66%

basics

~20 s

No. First separate 'we looked and it is not there' from 'we could not have seen it'. A search is only evidence where a source covered that host and window, retained the data, and would have recorded the described activity.

open as a page

Given VPN concentrator logs and CI runner job logs, how do you date an intrusion's spread?

level: middleimportance: must knowfreq 58%

basics

~20 s

Build one entity table — hosts, accounts, credentials — each with earliest and latest observed adversarial activity and the record proving it. Join the two sources on the concentrator-assigned address inside its session window, and mark every cell observed or inferred.

open as a page

An internet-facing file-transfer appliance's access log shows POSTs to an unknown .aspx page in its web root — is that enough to declare an intrusion?

level: middleimportance: must knowfreq 66%

basics

~20 s

Usually yes. A page in the appliance's web root that appears in no vendor manifest, driven from outside with command-shaped parameters, is an artefact no legitimate process explains — enough to declare, though the log proves no code ran.

open as a page

Executives want to pay an extortion demand to prevent publication — what must the pre-decided ransom position answer?

level: principalimportance: must knowfreq 57%

basics

~20 s

It must separate buying a decryption tool from buying a promise to delete stolen data, and settle in advance who signs, whether sanctions screening and insurer consent allow payment at all, and that engaging a negotiator is not the same as paying.

open as a page

A national CERT says one of your public IPs attacked another company at 02:11 UTC — what do you establish first?

level: juniorimportance: should knowfreq 54%

basics

~20 s

Turn the report into an asset and a time window. Normalise the timestamp, then use NAT, proxy or DHCP records together with the source port to find which internal host held that public address at that exact moment.

open as a page

What does declaring a security incident commit an organisation to that continuing to investigate does not?

level: juniorimportance: should knowfreq 58%

basics

~20 s

Declaring turns an open investigation into a formal intrusion response: evidence must be preserved rather than remediated away, the cyber insurer normally has to be notified, the work moves under legal counsel, and named people gain authority to disconnect systems.

open as a page

In a ransomware playbook, what must pre-delegated authority to disconnect the virtualisation management network specify?

level: middleimportance: should knowfreq 50%

basics

~20 s

A tight observable trigger, a bounded scope with explicit never-touch systems, an isolation method that preserves evidence, a notify-within deadline, who may reconnect and on what proof, and contractual cover so the delegate actually acts.

open as a page

A compromised identity has read-only access everywhere and no write anywhere — why can that still be a top-severity intrusion?

level: middleimportance: should knowfreq 61%

basics

~20 s

Because severity is graded on what was reached, not on what was broken. A directory-wide, warehouse-wide reader reaches regulated records, secrets left in resource metadata, and a complete map of the estate. Confidentiality loss requires no write at all.

open as a page

Why is a retained DFIR firm hired through outside counsel, and what changes in how you write findings?

level: middleimportance: should knowfreq 46%

basics

~20 s

Counsel engages the firm so its work informs legal advice and may be shielded from later disclosure. Notes then carry observed artefacts, sources and timestamps, never speculation about fault. The underlying logs and evidence are never protected.

open as a page

Your managed service provider says it was breached and its remote-support account in your estate may have been used — how do you scope it?

level: seniorimportance: should knowfreq 57%

basics

~20 s

Scope by the access, not by your alerts. Enumerate everything that identity could reach and every secret it could read, then reconstruct what it actually did from records you hold, and remediate the access whether or not misuse is proven.

open as a page

Twenty hours into a declared intrusion the scope doubles — why is upgrading the severity grade easier than downgrading it?

level: seniorimportance: should knowfreq 56%

basics

~20 s

Upgrading rests on positive evidence: new reach you can point at. Downgrading requires proving the earlier reach never existed, and a missing log record is not that proof — the logging may have been off, expired, or blind to the technique.

open as a page

You declared an intrusion at 02:00 on a burst of admin password-reset events that proved to be an approved bulk-reset script — what should the bar have required first?

level: seniorimportance: should knowfreq 44%

basics

~20 s

One authorisation check before the word, time-boxed. Windows 4724 proves a privileged reset happened, never who authorised it, so the bar must require the change record and a call to the named system owner, declaring anyway if nobody answers.

open as a page

Your earliest logs aged out at 90 days and an executive wants one intrusion start date — what do you commit to?

level: principalimportance: should knowfreq 42%

basics

~20 s

Commit to what the evidence supports: earliest observed activity with its date and citation, plus an explicit statement that the window before the retention edge cannot be assessed. Never convert an absence of records into a start date.

open as a page

Counsel wants a suspected insider's account left live to gather evidence; the CISO wants it disabled now. Who decides?

level: principalimportance: should knowfreq 38%

basics

~20 s

Neither function outranks the other, so the tie goes to the accountable executive the plan names, with HR present because cutting an employee's access is an employment act. Take the reversible option, time-box it, record the rationale.

open as a page

A foothold artefact predates your intrusion timeline by six months: how do you test it before moving patient zero back?

level: seniorimportance: nice to knowfreq 34%

basics

~20 s

Treat it as a hypothesis, not a finding. Test for positive linkage — shared unique artefacts, credentials, infrastructure — check continuity across the gap, and reconcile it against records of authorised activity before re-dating anything.

open as a page

An extortion leak site lists your company with a 2.1 TB claim and a 72-hour timer — what does that prove?

level: seniorimportance: nice to knowfreq 31%

basics

~20 s

It proves the actor published a claim and, if a sample is posted, possesses at least what is in that sample. The volume figure is unverified, the timer is a negotiating lever they set, and absence from the site would prove nothing.

open as a page

A departing employee bulk-exported an HR dataset. Who must you consult before examining their HRIS audit trail?

level: seniorimportance: nice to knowfreq 32%

basics

~20 s

Examining a named employee's records needs HR as data owner, the privacy office for a documented lawful basis, counsel for the legal posture, and in several European jurisdictions consultation with the works council before behaviour-monitoring data is analysed.

open as a page

The breached provider refuses to share the logs that would show whether its account touched your estate — what do you do?

level: principalimportance: nice to knowfreq 32%

basics

~20 s

Stop waiting for evidence you cannot compel. Set an explicit working assumption that the access was used, remediate on that basis, escalate commercially for narrow tenant-specific artefacts, and report the residual uncertainty plainly rather than as an all-clear.

open as a page

A data owner disputes the classification label on tables an intruder read — how do you settle the intrusion's grade?

level: principalimportance: nice to knowfreq 33%

basics

~20 s

Grade on what the columns actually contain, not only on the label. Hold the conservative grade as explicitly provisional, sample the real values from the columns the query records name, escalate to whoever is accountable for the label rather than to whoever disputes it, and record the basis.

open as a page

Your cyber policy demands prompt notice and panel counsel, and only the CISO may declare — how do you make out-of-hours declaration workable?

level: principalimportance: nice to knowfreq 31%

basics

~20 s

Split the authority. Pre-delegate in writing to a named duty officer the right to declare and contain against a standing threshold, and keep the acts that bind the company on a pre-cleared path with named fallbacks.

open as a page