DJN2: Incident Response Incident Reporting Template
Design by Paradigm | Incident Reporting
Template
SECTION A: INCIDENT DETAILS
Incident number(s): HDE- 1001, 1050, and 1072
Incident date(s): 13 December
Report author:
Report date: 7 July 2025
Summary of incident: The incident occurred when multiple engineers at Design by
Paradigm experienced server performance issues with
their Pro-Engineer CAD application. Multiple users stated
the application became slow and unresponsive, resulting in
them contacting the helpdesk for further investigation.
The Operations team identified that the fileserver was
experiencing high utilization and following SOP, rebooted
the server.
After this, additional tickets were created after users
started to experience latency on their devices.
After further investigation of our SIEM too, I believe an
unverified update from an undetermined source was applied
to the server which resulted in the increased utilization on
the GUP and CPU. Furthermore, there are
multiple remote connections established with the server to
unkown IP addresses.
Impacted system(s): WIN-6JNN6RLT6IL
Primary function of the File storage for Pro-Engineer
impacted system(s):
Impacted user(s): Maya Patel, Diego Martin, Alex Lee
Incident timeline: • 13 Dec 10:00 AM: first incident was reported
(HDE-1001)
o Shortly after this ticket, operations quickly
identified the storage server experiencing
high utilization and began remediation
efforts immediately. It was unsuccessful.
Followed SOP
• 13 Dec 03:14 PM: 2nd incident reported (HDE-1050)
• 13 Dec 03:20 PM: 3rd incident reported (HDE-1072)
PAGE 1
, DJN2: Incident Response Incident Reporting Template
• Tickets Were Assigned And Escalated To Me ()
o Remediation Immediately Took Place By
Removing Mining Software, Blocking The
Port
In Our Firewall, And Re-Enabling Window’s
Defender
Functional Impact:
(See Section: Glossary) ☐HIGH ☒MEDIUM ☐LOW ☐NONE
Incident Priority:
☒HIGH ☐MEDIUM ☐LOW
Additional Notes: This Was Categorized As A Medium Functional Impact
As The Organization Lost Its Ability To Provide Critical
Services To A Few Of Its Employees.
Priority Was Categorized As High Due To The Confirmed
Unauthorized Access, Successful Phishing, Compromise Of A
Critical System And The Active External Connection To A
Suspicious IP.
WIN-6JNN6RLT6IL Being An Application Server, Its
Degradation Impacted Productivity, Creating Real Business
Disruption. With The Presence Of Xmrig, Although A Legal
Tool, It Was Deployed Without Authorization. Any
Unauthorized Code Execution Should Be Escalated
Immediately.
A Spoofed Email Successfully Tricked An Admin Into
Installing Malicious Software. This Reveals A User-Level
And Process-Level Vulnerability. The Compromised
Server Was Communicating With An Unrecognized
Remote Host Which Opens The Door For Future Or Hidden
Payloads.
As A Result, It’s Creating Work Stoppage For Multiple
Employees. This Incident Was Caused Due To An
Administrator Running An Update From An Email That
Was Not Verified Prior To Downloading It To Its System.
Subsequently Causing Users To Have As Stated Above, Their
Application Running Slow And Timing Out.
In The Future It Is Recommended That Emails Be Verified
And
Properly Scanned To Ensure Malicious Content Is Not
Exposed To Design By Paradigm’s Servers.
Incident Type: (Check All That Apply)
☒Compromised System ☐Lost Equipment/Theft
☐ Compromised User Credentials ☐Physical Break-In
(E.G., Lost Password) ☒Social Engineering (E.G., Phishing)
☐ Network Attack (E.G., Dos) ☐Law Enforcement Request
☒Malware (E.G., Virus, Worm, Trojan) ☐Policy Violation (E.G., Acceptable Use)
☐ Reconnaissance (E.G., Scanning, ☐Other: Click Or Tap Here To Enter Text.
Sniffing)
Design by Paradigm | Incident Reporting
Template
SECTION A: INCIDENT DETAILS
Incident number(s): HDE- 1001, 1050, and 1072
Incident date(s): 13 December
Report author:
Report date: 7 July 2025
Summary of incident: The incident occurred when multiple engineers at Design by
Paradigm experienced server performance issues with
their Pro-Engineer CAD application. Multiple users stated
the application became slow and unresponsive, resulting in
them contacting the helpdesk for further investigation.
The Operations team identified that the fileserver was
experiencing high utilization and following SOP, rebooted
the server.
After this, additional tickets were created after users
started to experience latency on their devices.
After further investigation of our SIEM too, I believe an
unverified update from an undetermined source was applied
to the server which resulted in the increased utilization on
the GUP and CPU. Furthermore, there are
multiple remote connections established with the server to
unkown IP addresses.
Impacted system(s): WIN-6JNN6RLT6IL
Primary function of the File storage for Pro-Engineer
impacted system(s):
Impacted user(s): Maya Patel, Diego Martin, Alex Lee
Incident timeline: • 13 Dec 10:00 AM: first incident was reported
(HDE-1001)
o Shortly after this ticket, operations quickly
identified the storage server experiencing
high utilization and began remediation
efforts immediately. It was unsuccessful.
Followed SOP
• 13 Dec 03:14 PM: 2nd incident reported (HDE-1050)
• 13 Dec 03:20 PM: 3rd incident reported (HDE-1072)
PAGE 1
, DJN2: Incident Response Incident Reporting Template
• Tickets Were Assigned And Escalated To Me ()
o Remediation Immediately Took Place By
Removing Mining Software, Blocking The
Port
In Our Firewall, And Re-Enabling Window’s
Defender
Functional Impact:
(See Section: Glossary) ☐HIGH ☒MEDIUM ☐LOW ☐NONE
Incident Priority:
☒HIGH ☐MEDIUM ☐LOW
Additional Notes: This Was Categorized As A Medium Functional Impact
As The Organization Lost Its Ability To Provide Critical
Services To A Few Of Its Employees.
Priority Was Categorized As High Due To The Confirmed
Unauthorized Access, Successful Phishing, Compromise Of A
Critical System And The Active External Connection To A
Suspicious IP.
WIN-6JNN6RLT6IL Being An Application Server, Its
Degradation Impacted Productivity, Creating Real Business
Disruption. With The Presence Of Xmrig, Although A Legal
Tool, It Was Deployed Without Authorization. Any
Unauthorized Code Execution Should Be Escalated
Immediately.
A Spoofed Email Successfully Tricked An Admin Into
Installing Malicious Software. This Reveals A User-Level
And Process-Level Vulnerability. The Compromised
Server Was Communicating With An Unrecognized
Remote Host Which Opens The Door For Future Or Hidden
Payloads.
As A Result, It’s Creating Work Stoppage For Multiple
Employees. This Incident Was Caused Due To An
Administrator Running An Update From An Email That
Was Not Verified Prior To Downloading It To Its System.
Subsequently Causing Users To Have As Stated Above, Their
Application Running Slow And Timing Out.
In The Future It Is Recommended That Emails Be Verified
And
Properly Scanned To Ensure Malicious Content Is Not
Exposed To Design By Paradigm’s Servers.
Incident Type: (Check All That Apply)
☒Compromised System ☐Lost Equipment/Theft
☐ Compromised User Credentials ☐Physical Break-In
(E.G., Lost Password) ☒Social Engineering (E.G., Phishing)
☐ Network Attack (E.G., Dos) ☐Law Enforcement Request
☒Malware (E.G., Virus, Worm, Trojan) ☐Policy Violation (E.G., Acceptable Use)
☐ Reconnaissance (E.G., Scanning, ☐Other: Click Or Tap Here To Enter Text.
Sniffing)