Incident response and daily operations
Use a repeatable investigation workflow and daily health checklist without destroying evidence or turning approved DNN maintenance into alert noise.
Not rated yet
Daily checklist
- Confirm Dashboard and Pulse data are current and no collection endpoint is returning HTML/error
in place of JSON.
- Confirm WAF and Advisory Shield modes match policy and review new High/Critical signals.
- Review Realtime Monitor and Scan Results with safe items hidden.
- Confirm FIM health, last scan, baseline age, open violations, and scheduled-job success.
- Review DNN Event Log and recent Host/SuperUser changes.
- Confirm notification and report jobs ran successfully.
Incident workflow
An upgrade may be one eradication step, but it is never the sole proof of eradication. Preserve
evidence before upgrading, because replaced core files and database migrations can otherwise hide
the original timeline. Do not approve a new FIM baseline merely because the upgrade completed.
- Validate: confirm the event time, path/route, user/client context, action, engine state, and
whether the evidence is a block, observation, error, or integrity change.
- Preserve: export relevant rows and retain quarantine/FIM copies and server logs. Do not clear
evidence before it is captured.
- Contain: enable the applicable strict/prevention control, restrict the route, quarantine a
confirmed malicious file, or isolate the server according to business impact.
- Investigate: search for persistence, sibling payloads, modified configuration, unexpected
DLLs/modules, privileged-account changes, outbound connections, and related WAF events.
- Eradicate and recover: remove the root cause, restore trusted files/database, rotate exposed
secrets when indicated, and apply the DNN/vendor fix.
- Validate: run malware and FIM scans, test the site, confirm control health, and monitor for
recurrence.
- Close and learn: document scope, root cause, actions, residual risk, and preventive changes.
Follow NIST SP 800-61 Revision 3 concepts for preparation, detection, response, recovery, and
continuous improvement. A finding should have an owner and disposition: confirmed incident,
benign approved change, false positive with bounded tuning, or unresolved.
Avoiding alert fatigue in DNN
Use Maintenance Mode for approved DNN/module/skin changes. Exclude high-churn data and cache
locations from FIM, but continue to watch for executable server code appearing under upload
folders. Do not suppress an entire route or extension because one benign application uses it;
tune the smallest path, role, verb, and behavior combination that explains the false positive.
Was this page helpful?