Building a Compromise-Assessment Capability and Cordon
Capability lead, architect and hands-on engineer · 2025
I built the method, investigation workflow and collection tool used for proactive assessments and post-incident scoping.
Context
Assessments may be driven by regulatory expectations, executive assurance, a major incident or weak environment segmentation. The method must adapt to the trigger while preserving evidence quality and confidentiality.
Problem
The organization needed a repeatable way to test for active or historical compromise across endpoints and container platforms, but no existing process or tool matched the required OpenShift collection model.
Approach
Separate pre-compromise and post-compromise assessment paths, then use hypotheses, forensic artifacts, relevant IOCs and IOAs, persistence behaviors and a maintained hunting library to guide collection and analysis.
Implementation
- Defined scope, evidence requirements, confidence language and reporting structure.
- Used offline collection or Velociraptor and VQL where appropriate.
- Created Cordon to collect OpenShift forensic evidence with simple oc commands and without creating debug pods.
- Connected findings to containment, telemetry improvement and detection engineering.
Decisions
Design two assessment paths
Proactive assurance and post-incident scoping begin with different evidence and decision pressure.
The methodology requires disciplined scoping before collection starts.
Collect without debug pods
Native oc-driven acquisition reduces changes to the investigated environment.
Collection is intentionally bounded by available permissions and artifacts.
Report evidence limits explicitly
A defensible conclusion depends on what could actually be tested.
The result may be less absolute, but it is more useful for risk decisions.
Outcome
The team gained a repeatable assessment process, a safer way to collect OpenShift evidence and a clear path from findings to response and detection work.
Platforms & methods
Cordon · OpenShift · oc · Velociraptor · VQL · EDR · SIEM · MITRE ATT&CK