# 🔌 Role Profile: Network Infrastructure Team / System Team

![Network System Team Avatar](../assets/Network%20System%20Avatar.png)

## 📋 Role Overview
The **Network Infrastructure Team / System Team** executes network and system containment requested by the SOC, performs firewall blocks, account changes, or system actions when the SOC lacks direct permissions, supports eradication/recovery actions, and coordinates closely with the SOC.

---

## 🎯 Mandatory Responsibilities (SOP / Authority Matrix)
- ⚡ **Execute Technical Containment**: Execute network and system containment actions requested by the SOC.
- 🛡️ **Execute Privileged Actions**: Perform firewall IP/domain blocks, Active Directory account modifications, or system isolation actions when SOC lacks native administrative permissions.
- 🛠️ **Support Eradication & Recovery**: Support technical eradication (reimaging workstations, patching, system hardening) and system recovery actions.
- 🤝 **Coordinate with SOC**: Maintain continuous technical coordination with SOC during containment and remediation workstreams.

---

## 🎮 TTX Scenario Responsibilities (Loan Ransomware Incident)
- Apply perimeter firewall block for C2 IP `185.123.45.6`.
- Lock compromised AD account `j.smith` and terminate active SMB sessions on `\\FS01`.
- Reimage victim workstation `LOAN-LAPTOP-042` with approved baseline image and EDR sensor.

---

## 📝 Action Checklist
- [ ] Receive technical containment requests from SOC L2/L3.
- [ ] Implement firewall IP/domain blocks.
- [ ] Execute AD account lockouts, credential resets, and session terminations.
- [ ] Reimage affected workstations and re-verify baseline hardening.
- [ ] Restore system files from clean backups upon approval.
