Short-Term Containment
Definition
Immediate actions taken after incident confirmation to stop an attack from spreading, without waiting for full scope analysis. Distinguished from long-term containment, which stabilises the environment for sustained investigation.
- Timing
- Immediately after incident confirmation
- Goal
- Stop the attack from spreading further
- Contrasted with
- Long-term containment, which stabilises the environment for sustained investigation
- Typical actions
- Network isolation, disabling compromised accounts, blocking malicious IPs
Common questions
Why act before full scope analysis is complete?+
Waiting for a complete picture of the attack's scope while it continues to spread risks far greater damage, so short-term containment trades some investigative completeness for stopping active harm, accepting that some evidence-gathering and root-cause work happens in parallel or afterward.
What is the risk of short-term containment done carelessly?+
Isolating or shutting down systems too abruptly can destroy volatile evidence such as memory contents and active network connections, and can also tip off an attacker who is still present, so responders try to capture key volatile evidence before or during containment where feasible.
Related terms
- Attacker-Alerting Risk
- The risk that a containment action signals to the attacker that they have been detected, potentially triggering destructive countermeasures on systems they...
- Network Isolation
- Disconnecting a compromised host from all network interfaces while leaving it powered on. Preserves volatile memory contents but removes the attacker's communication...
- Traffic Blocking
- Adding firewall rules, null routes, or DNS sinkholes to deny communication between attacker-controlled infrastructure and the victim network. Effective against external command-and-control...
- VLAN Segmentation
- Moving a compromised device or subnet into a separate VLAN with restrictive access control lists, limiting lateral movement to other network segments...
- Volatile Evidence
- Data that exists only while a system is running: active processes, logged-in sessions, network socket state, decryption keys in memory, and command...