7. Incident Response

Lesson#97 of 107 in project Theory

Something like this

Alert
Triage
Investigation
Containment
Eradication
Recovery
Lessons learned

They should learn:

Alert triage

  • Is this real?
  • Is it malicious?
  • Is it a false positive?
  • How severe is it?

Investigation

  • What happened?
  • Which account?
  • Which machine?
  • Which IP?
  • How did the attacker get in?
  • What did they do?
  • Did they move laterally?
  • Was data accessed?

Containment

Understand concepts such as:

  • isolating endpoint
  • disabling account
  • blocking IP/domain
  • killing malicious process
  • removing persistence