Step 7 of 8 — Remediation
Step 7 of 8

Auto-generated remediation

HoneyNet drafted 4 remediation steps based on the incident. Review and approve — or reject steps that don't fit your runbook.

⏳ 3 of 4 steps approved
Incident #INC-2024-0613-001
1
Disable honeypot credential in Entra ID
Disable fake_admin@corp.local in Entra ID. The account was a lure — no production access affected.
✓ Approved — auto-executed
2
Rotate /prod/legacy/db-admin secret
Invalidate the fake PG connection string in Secrets Manager and redeploy with a new canary value. Takes ~40 seconds.
✓ Approved — auto-executed
3
Block 185.220.101.47 + /25 subnet
Add IP block at Entra ID Conditional Access, AWS Security Group, and internal WAF. The /25 subnet (185.220.101.0/25) is a known Tor exit range.
✓ Approved — auto-executed
4
Open Jira incident ticket
Create a P2 Jira ticket in SECOPS with full timeline, MITRE mapping, and blocked IPs. Assign to on-call engineer.
🔄
Next: rotate the burned lure
The honeypot credential fake_admin@corp.local was exposed. HoneyNet will retire it and deploy a fresh lure automatically.