Register Login

Incident response and daily operations

Use a repeatable investigation workflow and daily health checklist without destroying evidence or turning approved DNN maintenance into alert noise.

Not rated yet

Daily checklist

  • Confirm Dashboard and Pulse data are current and no collection endpoint is returning HTML/error in place of JSON.
  • Confirm WAF and Advisory Shield modes match policy and review new High/Critical signals.
  • Review Realtime Monitor and Scan Results with safe items hidden.
  • Confirm FIM health, last scan, baseline age, open violations, and scheduled-job success.
  • Review DNN Event Log and recent Host/SuperUser changes.
  • Confirm notification and report jobs ran successfully.

Incident workflow

An upgrade may be one eradication step, but it is never the sole proof of eradication. Preserve evidence before upgrading, because replaced core files and database migrations can otherwise hide the original timeline. Do not approve a new FIM baseline merely because the upgrade completed.

  1. Validate: confirm the event time, path/route, user/client context, action, engine state, and whether the evidence is a block, observation, error, or integrity change.
  2. Preserve: export relevant rows and retain quarantine/FIM copies and server logs. Do not clear evidence before it is captured.
  3. Contain: enable the applicable strict/prevention control, restrict the route, quarantine a confirmed malicious file, or isolate the server according to business impact.
  4. Investigate: search for persistence, sibling payloads, modified configuration, unexpected DLLs/modules, privileged-account changes, outbound connections, and related WAF events.
  5. Eradicate and recover: remove the root cause, restore trusted files/database, rotate exposed secrets when indicated, and apply the DNN/vendor fix.
  6. Validate: run malware and FIM scans, test the site, confirm control health, and monitor for recurrence.
  7. Close and learn: document scope, root cause, actions, residual risk, and preventive changes.

Follow NIST SP 800-61 Revision 3 concepts for preparation, detection, response, recovery, and continuous improvement. A finding should have an owner and disposition: confirmed incident, benign approved change, false positive with bounded tuning, or unresolved.

Avoiding alert fatigue in DNN

Use Maintenance Mode for approved DNN/module/skin changes. Exclude high-churn data and cache locations from FIM, but continue to watch for executable server code appearing under upload folders. Do not suppress an entire route or extension because one benign application uses it; tune the smallest path, role, verb, and behavior combination that explains the false positive.

Was this page helpful?

0 comments

Comments are reviewed before they appear.