Summary
In this chapter, we learned how to identify from a practical case the best strategy for performing first-response procedures.
We also learned in a very practical way how to perform first-response procedures using different tools to obtain images of memory, disk, and forensic artifacts.
In this first part of the book, we learned the fundamentals of the threat landscape and IR procedures. In the next part, we will learn about the different types of adversaries, their modus operandi (MO), and some frameworks that will help us identify their tactics, techniques, and procedures (TTPs) to look for specific artifacts or evidence.