Perspective V Docs
Tabletop drills

Tabletop Drill Report: SSH Egress Policy Incident

Simulated event: new outbound TCP/22 block detections appear in kernel/UFW logs during normal operations, requiring containment verification, exception-control quality checks, and integrity decision framing.

Metadata

  • Drill id: TT-20260415T220000Z
  • Date (UTC): 2026-04-15
  • Scenario class: security incident (outbound SSH policy breach signal)
  • Runbooks exercised:
    • docs/operations/governance/incident-response-playbook.mdx
    • docs/operations/governance/host-integrity-checklist.mdx
  • Authority model exercised: single-owner approval gates

Scenario

Simulated event: new outbound TCP/22 block detections appear in kernel/UFW logs during normal operations, requiring containment verification, exception-control quality checks, and integrity decision framing.

Timeline Walkthrough

0 to 5 minutes (contain)

  • Confirmed baseline policy expectation: permanent deny outbound TCP/22 with logging.
  • Confirmed owner-gated exception model remains required before any temporary allow.

5 to 30 minutes (collect)

  • Mapped required evidence set from playbook:
    • process/socket attribution
    • firewall state snapshots
    • sshd effective auth matrix
    • fail2ban sshd status
    • policy log trail

30 to 120 minutes (eradicate/recover)

  • Verified required response path:
    • no direct broad rule changes
    • temporary exception only through scripted workflow with full audit fields
    • mandatory close verification and post-close sweep

Same-day revalidation

  • Verified closure gate requirements:
    • deny-by-default restored
    • blocked-detection monitoring still active
    • residual risks converted to tracked next steps where needed

Host Integrity Checklist Coverage

Checklist items validated in simulation sequence:

  • baseline capture set required before cleanup actions
  • persistence sweep scope remains systemd + cron + startup scripts + authorized keys
  • service/package integrity checks include control-state verification and unexpected port exposure review
  • decision gate requires explicit rebuild-vs-recovery posture statement with owner sign-off

Outcome

  • Result: pass
  • Runbook quality: sufficient for controlled response under change pressure
  • Gaps identified:
    • keep one live exception open/close drill evidence attached to incident follow-up task
    • keep one Discord rendering verification sample for blocked-detection + exception cycle

Follow-up Mapping

  • Follow-up remains tracked in docs/state/next-steps.mdx under Security Incident Follow-up:
    • Discord render-quality verification
    • controlled exception drill evidence cycle

On this page