Incident analysis and containment – investigating and stopping the spread of cyberattacks
Cybersecurity incident analysis and containment phases are usually mentioned together because they are two critical steps that happen right after each other. By analyzing the incident, the incident response team understands the infection scope and the threat, allowing immediate action to contain it and minimize the damage.
Incident analysis
Incident analysis is sometimes underrated as a part of the incident response process. There are many reasons for that, but the most important is time. Also, we will focus on the technical aspects and possible jitters in the upcoming chapters. We are here to define the process.
Incident analysis starts after successful verification and confirmation. The team gets the infected scope and the Indicators of Attack (IOAs), or in the ideal case, an initial set of Indicators of Compromise (IOCs). Then, the infected assets should be thoroughly analyzed...