7. Incident Response
Something like this
Alert↓Triage↓Investigation↓Containment↓Eradication↓Recovery↓Lessons learned
They should learn:
Alert triage
- Is this real?
- Is it malicious?
- Is it a false positive?
- How severe is it?
Investigation
- What happened?
- Which account?
- Which machine?
- Which IP?
- How did the attacker get in?
- What did they do?
- Did they move laterally?
- Was data accessed?
Containment
Understand concepts such as:
- isolating endpoint
- disabling account
- blocking IP/domain
- killing malicious process
- removing persistence