🇮🇳 CERT-In Directions 2022

CERT-In Advisory Response Drill

Practice the actual 6-hour reporting workflow. Simulated advisory, countdown timer, CERT-In notification form drill, and decision tree for what must be reported.

📄 Simulated CERT-In Advisory

This is a simulated advisory in the actual CERT-In format. Use this to practice your first 30 minutes — receiving an advisory, assessing applicability, and starting your response clock.

CERT-IN SECURITY ADVISORY — CIAD-2025-0147
━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━

Advisory ID : CIAD-2025-0147
Date : 30-Jul-2026
Severity : CRITICAL
Affected : Apache HTTP Server 2.4.x (all versions before 2.4.62)
CVE Reference : CVE-2024-38476, CVE-2024-38474, CVE-2024-38477

DESCRIPTION
Multiple critical vulnerabilities have been identified in Apache HTTP Server versions prior to 2.4.62. Exploitation of these vulnerabilities could allow a remote attacker to execute arbitrary code, bypass security restrictions, or cause a denial of service condition.

CVE-2024-38476 — Severity: CRITICAL (CVSS 9.1)
Information disclosure vulnerability. Malicious backends can manipulate responses to include response headers from HTTP/2 connections, potentially resulting in information disclosure and server-side request forgery.

CVE-2024-38474 — Severity: CRITICAL (CVSS 9.1)
Improper escaping in mod_rewrite. Substitution encoding issues in mod_rewrite may allow attackers to map URLs to filesystem locations that are permitted to be served by the server but should not be.

AFFECTED SYSTEMS
Apache HTTP Server: All versions 2.4.x < 2.4.62
Operating Systems: Linux, Windows, FreeBSD — all platforms


ACTIVE EXPLOITATION
CERT-In has received reports of active exploitation of CVE-2024-38476 targeting Indian government and financial sector infrastructure. Exploitation observed in the wild as of 30-Jul-2026.

IMPACT
• Execution of arbitrary OS commands
• Unauthorised access to sensitive data
• Server compromise and lateral movement
• Bypass of authentication controls


REMEDIATION
1. Upgrade Apache HTTP Server to version 2.4.62 or later immediately
2. If upgrade not possible: disable mod_rewrite or apply vendor workarounds
3. Review Apache access logs for indicators of exploitation
4. Apply WAF rules to block known exploit patterns


IOCs — Network
103.21.124.7, 185.220.101.47, 45.9.148.22
User-Agent patterns: Mozilla/5.0 (compatible; exploit/4.0)


REPORTING
If you have been compromised via this vulnerability, report to CERT-In within 6 hours:
Email: incident@cert-in.org.in | Phone: 1800-11-4949
Portal: https://incident.cert-in.org.in


━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━
CERT-In | Ministry of Electronics & Information Technology | Government of India

Discussion Questions — First 15 Minutes

Do you run Apache HTTP Server in your environment? Who knows the current version?
Who receives CERT-In advisories in your organisation? Does it reach the right person within 15 minutes?
Is there a defined process for assessing "is this advisory applicable to us"? Who owns that assessment?
The advisory says active exploitation is happening targeting Indian infra. Does this change your priority level?
What are the IOC IPs above? Have you seen them in your logs in the last 30 days?

⏰ 6-Hour CERT-In Reporting Timer

Start this timer the moment your team confirms a reportable cyber incident. Under CERT-In Directions 2022, you must file an incident report within 6 hours. Use this to practice working against a real deadline.

6:00:00
Time remaining to file CERT-In report
Timer not started

Key Actions During the 6-Hour Window

T+0:00 0:00 hrs
Incident confirmed — timer starts. Notify CISO and escalate chain immediately.
T+0:30 0:30 hrs
Contain immediate spread — isolate affected systems. Do not destroy evidence.
T+1:00 1:00 hrs
Forensic triage underway. Scope assessment — what systems, what data?
T+1:30 1:30 hrs
Legal and compliance notified. Determine if incident is reportable (it likely is).
T+2:00 2:00 hrs
Begin drafting CERT-In notification. Use portal or email. Incomplete is OK — file what you know.
T+2:30 2:30 hrs
Check for other regulatory triggers: RBI (if BFSI), SEBI, IRDAI, NCIIPC (if CII).
T+3:00 3:00 hrs
First draft of CERT-In report should be ready for CISO review.
T+4:00 4:00 hrs
Report filed. Confirmation email/acknowledgement from CERT-In received and saved.
T+5:00 5:00 hrs
Begin preparing update report — CERT-In will ask for follow-up within 24 hours.
T+6:00 6:00 hrs
DEADLINE — Report must be submitted. If not filed, violation of CERT-In Directions 2022.

✅ 6-Hour Response Checklist

Incident confirmed and documented T+0
Record the exact time and date of detection/confirmation. This starts all regulatory clocks.
CISO and senior management notified T+0-15 min
Use documented escalation path — not just WhatsApp. Get formal acknowledgement.
Immediate containment without evidence destruction T+0-30 min
Isolate affected systems. Do NOT wipe or reimage until forensic image taken.
Incident Response team activated T+15 min
Named IR team with defined roles — lead, forensics, communications, legal, management liaison.
Evidence preservation started T+30 min
Memory dump, disk image, log export before any remediation. Hash all evidence.
Scope assessment completed T+30-60 min
What systems affected? What data? What services impacted? How many users?
CERT-In notification category determined T+60 min
Check CERT-In Directions 2022 Section 3(i) — is this a listed reportable event?
Legal / compliance team engaged T+60 min
Determine all regulatory reporting obligations. Different regulators have different timelines.
CERT-In report draft started T+90 min
Begin filling the notification even with incomplete information. File partial, update later.
CERT-In report reviewed by CISO T+2-3 hrs
Legal and technical accuracy review before submission.
CERT-In report filed Before T+6 hrs
Via portal (incident.cert-in.org.in) or email (incident@cert-in.org.in). Save confirmation.
Other regulators notified as required Varies
RBI (2 hrs if BFSI), NPCI, NCIIPC, SEBI — as applicable.
Customer/user communication decision made T+3-4 hrs
Determine if affected users need to be notified. Draft holding statement.
CERT-In acknowledgement saved After filing
CERT-In will send an acknowledgement email/reference number. Save it.
24-hour follow-up report scheduled After filing
CERT-In will request a detailed follow-up within 24 hours. Schedule this task now.

📝 CERT-In Notification Form — Practice Drill

Practice filling the CERT-In incident notification under time pressure. This mirrors the information CERT-In requires. Complete this in under 20 minutes as a drill.

🌳 Must I Report to CERT-In? — Decision Tree

Use this to determine reporting obligation under CERT-In Directions 2022. Every question answered honestly leads to the correct regulatory conclusion.

1. Did your organisation experience a cyber incident involving IT systems?
Continue to next question
You are not required to report at this time. However, you must report if you later discover a breach.
2. Is the incident one of the 20 listed categories in CERT-In Directions 2022 Section 3(i)?
Mandatory reporting within 6 hours of knowledge.
Assume YES and file. CERT-In prefers over-reporting. The list is broad — most significant incidents qualify.
3. Is your organisation a Critical Information Infrastructure (CII) operator?
Enhanced reporting obligation. Also notify NCIIPC. Some incidents require 2-hour notification to sectoral regulator.
Standard 6-hour reporting applies. Still mandatory if incident qualifies.
4. Did the incident involve personal data of Indian citizens?
CERT-In + DPDP Act Section 8(6) notification to Data Protection Board required. Also check sector regulator.
CERT-In notification still required if incident qualifies. DPDP notification may not apply.
5. Has 6 hours passed since you confirmed knowledge of the incident?
File immediately. Delay is itself a violation. State in your report when you first had knowledge. Explain the delay.
File as soon as the report is reasonably complete. Incomplete filing is better than late filing.
Default position: If you are uncertain whether an incident qualifies for reporting, file with CERT-In. The penalty for non-reporting is significantly greater than the administrative burden of over-reporting. CERT-In explicitly encourages early, partial reports updated as investigation progresses.