Incident Response
U.S. FCEB Agencies
CISA requires U.S. FCEB agencies to:
-
Refer to the Supplemental Direction for ED 25-03:
- Run the “show checkheaps” and “show tech-support detail” commands.
- Ensure to save the full output off the device (preferably to an isolated system).
-
Generate a Core Dump:
- Generate a core dump from the affected Cisco device(s).
- Submit it through CISA’s Malware Next Generation platform.
-
Report Submission:
- Report the submission immediately via CISA’s 24/7 Operations Center ([email protected], 1-844-Say-CISA [1-844-729-2472], or CISA’s Incident Reporting System).
- Identify that the activity is related to FIRESTARTER.
After incident intake, CISA will provide guidance on next steps. If compromise is confirmed, this may include instructions to physically unplug the device from power to remove FIRESTARTER’s persistence. **Organizations should not unplug the device unless directed to do so by
Read the full article at CISA Advisories
Want to create content about this topic? Use Nemati AI tools to generate articles, social posts, and more.





