Introducing indicators of incidents
When an incident is being investigated the teams may perform operations in parallel depending on their area of expertise. However, they will all use indicators as part of their investigation to make determination about the attack and compromise as well as attempt to determine if there are any additional indicators to add to the list.
Types of indicators
There are three primary indicators incident responders work with and those include Indicators of Attack (IOAs), Indicators of Compromise (IOCs), and Indicators of Interest (IOIs). Let take a deeper look in to these.
IOAs are the precursors to a breach. Many IOAs are behavior related and dynamic in nature. What this means is the activity itself may not be malicious but other elements make it so. As an example, an attacker attempting to brute force their way in to the network. The process the attacker is using is not malicious, they are just trying to login. It is the behavior of trying multiple...