Pivoting with Detection Data
Course Content
0 / 25 completedLearning About Evidence Collection
Identifying Assets for Incident Response
Profiling Network Entities
Profiling Servers and Assets
Understanding the Incident Response Process
Reviewing the Incident Response Process
The Incident Handling Process
Course Overview
Incident Response Preparation
Understanding the Stakeholders
Identifying Protected Data
The Preparation Phase
Pivoting with Detection Data
The Detection and Analysis Phase
Incident Response Detection and Analysis
Hunting for More Data
Understanding Correlated Events
The Detection and Analysis Phase
Incident Response Containment, Eradication, and Recovery
The Containment, Eradication, and Recovery Phase
Incident Response Post-incident Analysis
Detailing SOC Metrics and Scopes
Wrapping up IR Policies and Procedures
The Post-incident Analysis Phase
Domain Summary