CISA udgiver værktøj til udvisningsstrategier for hændelsesrespons
juli 30, 2025 • César Daniel Barreto

On July 30, 2025, CISA released the Eviction Strategies Tool, a free and open-source toolset built to help defenders through the containment and eviction phases of incident response — the difficult work of removing an adversary from a network after a breach. Developed for CISA by MITRE and published under the MIT License, it lets responders generate a tailored eviction plan in minutes rather than assembling one by hand under pressure.
Two components: Playbook-NG and COUN7ER
The tool has two parts. Playbook-NG is a stateless web application: a defender feeds in MITRE ATT&CK technique IDs or a free-text description of the observed adversary activity, and it returns a matched set of recommended countermeasures. Those recommendations are drawn from COUN7ER, a database of atomic, post-compromise countermeasures mapped to adversary tactics, techniques, and procedures. Together they turn scattered incident findings into a structured, repeatable response plan.
Built for real incidents
Plans export to JSON, Word, Excel, or Markdown, and a previously exported JSON plan can be re-uploaded so countermeasures refresh as new findings arrive. The application is stateless by design — nothing persists once you navigate away, which matters when handling sensitive incident data. CISA also ships curated templates that double as tabletop-exercise scenarios. You can use it hosted on CISA’s website or self-host it from the GitHub repository.
Why it matters
For SOC and incident-response teams, free and vendor-neutral tooling for the eviction stage — usually the most ad hoc part of a response — is a rare and welcome thing. Even outside an active incident, it is worth running through in a tabletop to pressure-test how your team would evict a real intruder.

César Daniel Barreto
César Daniel Barreto er en anerkendt cybersikkerhedsskribent og -ekspert, der er kendt for sin dybdegående viden og evne til at forenkle komplekse cybersikkerhedsemner. Med omfattende erfaring inden for netværks sikkerhed og databeskyttelse bidrager han regelmæssigt med indsigtsfulde artikler og analyser om de seneste cybersikkerhedstendenser og uddanner både fagfolk og offentligheden.