Aula 7 de 7 · 10 min
Capstone: a tabletop exercise on an AI-evasion incident
Put the course together in a discussion-based exercise: a fictional company, an attack that slipped past its ML detection, a series of injects, and the questions a defending team should answer, with model answers.
Por enquanto esta página está em inglês.
This capstone is a tabletop exercise, not a live lab. Nothing is attacked and no tool is run. A tabletop is a structured discussion: a facilitator describes a scenario in stages (called injects), and the team talks through what it would notice, decide and do. CISA publishes ready-made tabletop exercise packages for organisations for exactly this reason: rehearsing decisions on paper finds gaps before a real incident does. The scenario below is fictional.
The scenario
Northwind Design is a fictional 60-person design agency. It runs an ML-based endpoint detection product on every laptop, a cloud email filter, and single sign-on for its apps. Its small IT team reviews alerts each morning. Nobody hunts proactively. Logs from laptops are kept for 14 days.
Inject 1: a quiet Monday
A designer reports that a “font pack” from a client’s shared folder would not open. The endpoint tool shows no alert for that laptop. Nothing else is unusual.
- Question 1: Is “no alert” a reason to close this report?
- Question 2: What evidence, other than the endpoint verdict, could you check right now?
Inject 2: an odd destination
Three days later, an IT staff member notices in the network logs that the same laptop has been making small, regular outbound connections to a cloud-hosted address the company has never used, roughly every ten minutes, including overnight.
- Question 3: Which ATT&CK tactics might this pattern relate to, and what hypothesis would you write?
- Question 4: What immediate containment would you consider, and what would you preserve first?
Inject 3: the account
Single sign-on logs show the designer’s account signed in to the file-sharing service at 03:00 from the laptop, and a large number of project files were downloaded. The designer was asleep.
- Question 5: Who needs to be informed now, inside and outside the company?
- Question 6: After recovery, what changes would stop a single missed detection from giving an attacker days of freedom?
Model answers
| Question | What a strong answer covers |
|---|---|
| 1 | No. A missing alert only means one model did not flag it. A file that fails to open is worth a look, especially from a shared folder. |
| 2 | The file’s origin and signature, what processes started on the laptop around that time, and the laptop’s outbound connections since then. |
| 3 | Command and control, and possibly exfiltration. Hypothesis: “If this laptop is compromised, a program that did not exist last week is making regular outbound connections, and it will appear in process and network logs.” |
| 4 | Isolate the laptop from the network while keeping it powered on; preserve logs and a disk image before they age out of the 14-day window; reset the user’s credentials and sessions from a clean machine. |
| 5 | Management, the incident lead and, depending on the data and jurisdiction, legal counsel, affected clients and any data-protection authority notification required by law. Follow NIST SP 800-61 style roles decided in advance. |
| 6 | Independent layers: outbound network visibility per app, sign-in anomaly alerts, canary files in shared folders, longer log retention, a regular hypothesis-driven hunt, and a rule that user reports are investigated even without an alert. |
Debrief questions for your team
- At which inject would your organisation have noticed first, and from which source?
- Which decisions would have needed someone who was not available?
- Which logs would already have been deleted by the time you looked?
- Where did the team trust one tool’s silence?
Where FireAI fits
In this scenario, the first independent evidence was an unfamiliar program on a laptop contacting a new destination. On a Mac, that is what FireAI is designed to surface: a new app must ask before connecting, allowed connections still appear on the world map and in activity history, and the kill switch refuses every new connection outside the home or office network in one click if a team decides to isolate the machine. FireAI does not scan files, so it complements endpoint detection rather than replacing it.
Para lembrar
- A tabletop rehearses decisions in discussion; nothing is attacked.
- User reports deserve investigation even when no tool raised an alert.
- Independent evidence (network, sign-in logs, canaries) turns a silent miss into a finding.
- Log retention, containment steps and notification duties should be decided before an incident.
Teste seus conhecimentos
1. What is a tabletop exercise?
- A live attack on production systems
- A structured discussion of a scenario in stages, with no systems attacked — Certo.
- A vulnerability scan
- A penetration test without permission
Tabletops rehearse decisions and communication through discussion of injects.
2. In the scenario, why was “no alert from the endpoint tool” not enough to close the first report?
- The tool was switched off
- A missing alert only means one model did not flag it; other evidence might — Certo.
- Alerts are never useful
- Fonts are always dangerous
Silence from one layer is not proof of safety. Other layers and user reports can reveal what a model missed.
3. When isolating a possibly compromised laptop, what should you preserve first?
- Nothing, wipe it immediately
- Logs and a disk image, before retention windows delete the evidence — Certo.
- The desktop wallpaper
- Browser bookmarks only
Evidence is needed to understand scope and prevent recurrence. Short retention windows make preservation urgent.
Praticar com o FireAI
Coloque esta lição em prática no seu próprio Mac.
- Autopilot: FireAI decides the easy connections for you — Let FireAI clear the easy decisions on its own, and always see why.
- Use Autopilot safely: what it decides, and how to correct it — Turn Autopilot on with a clear view of what it’s doing, and fix anything it gets wrong.
- Investigate a connection — Decide with the facts in front of you, not a vague warning.
- Threat lists (opt-in) — Check your traffic against public threat data without sending it anywhere.
- The World map — See where your data actually goes, not just a hostname you’d have to look up yourself.
- Security modes: Home, Coffee shop, Paranoid, Under attack — Match FireAI’s strictness to where your Mac actually is, in one tap.
Fontes
- CISA Tabletop Exercise Packages
- NIST SP 800-61 Rev. 3: Incident Response Recommendations
- MITRE ATT&CK
- MITRE D3FEND
- CISA: Eviction Strategies Tool
Coloque em prática no seu Mac
Teste todos os recursos grátis por 17 dias, sem cartão.