Summary
Incident response efforts, while following a uniform process, vary slightly based on the platforms or environments involved. This chapter looked at IR in computers, mobile devices, and AD.
IR on computers will follow the normal seven stages. On the other hand, when we looked at mobile device IR processes, we outlined that a slight modification has been made to the typical seven-stage IR process published by SANS. The mobile IR process includes the following main stages: identification, containment, eradication, recovery, and debriefing. In AD IR, there are five main types of incidents that must be handled: user account changes, password resets, security group changes, single-user numerous logons, and group policy changes. We looked at these and the required actions to be taken by admins have been outlined, along with a more detailed look into Windows startup processes and how to tell if something's wrong.
We also considered the attitudes of Microsoft, Amazon,...