Tabletop drills
Tabletop Drill Report: SSH Egress Policy Incident
Simulated event: new outbound TCP/22 block detections appear in kernel/UFW logs during normal operations, requiring containment verification, exception-control quality checks, and integrity decision framing.
Metadata
- Drill id: TT-20260415T220000Z
- Date (UTC): 2026-04-15
- Scenario class: security incident (outbound SSH policy breach signal)
- Runbooks exercised:
docs/operations/governance/incident-response-playbook.mdxdocs/operations/governance/host-integrity-checklist.mdx
- Authority model exercised: single-owner approval gates
Scenario
Simulated event: new outbound TCP/22 block detections appear in kernel/UFW logs during normal operations, requiring containment verification, exception-control quality checks, and integrity decision framing.
Timeline Walkthrough
0 to 5 minutes (contain)
- Confirmed baseline policy expectation: permanent deny outbound TCP/22 with logging.
- Confirmed owner-gated exception model remains required before any temporary allow.
5 to 30 minutes (collect)
- Mapped required evidence set from playbook:
- process/socket attribution
- firewall state snapshots
- sshd effective auth matrix
- fail2ban sshd status
- policy log trail
30 to 120 minutes (eradicate/recover)
- Verified required response path:
- no direct broad rule changes
- temporary exception only through scripted workflow with full audit fields
- mandatory close verification and post-close sweep
Same-day revalidation
- Verified closure gate requirements:
- deny-by-default restored
- blocked-detection monitoring still active
- residual risks converted to tracked next steps where needed
Host Integrity Checklist Coverage
Checklist items validated in simulation sequence:
- baseline capture set required before cleanup actions
- persistence sweep scope remains systemd + cron + startup scripts + authorized keys
- service/package integrity checks include control-state verification and unexpected port exposure review
- decision gate requires explicit rebuild-vs-recovery posture statement with owner sign-off
Outcome
- Result: pass
- Runbook quality: sufficient for controlled response under change pressure
- Gaps identified:
- keep one live exception open/close drill evidence attached to incident follow-up task
- keep one Discord rendering verification sample for blocked-detection + exception cycle
Follow-up Mapping
- Follow-up remains tracked in
docs/state/next-steps.mdxunder Security Incident Follow-up:- Discord render-quality verification
- controlled exception drill evidence cycle