Triaging and responding to alerts
Triaging and responding to alerts is one of if not the most important part of this whole process. No matter how many security products you have, no matter how well you have them configured, threat actors will always find a way if they have to. This is why responding to and accurately assessing alerts is crucial. Being able to contain a breach quickly and confidently can make or break a company. In this section of the chapter, we'll cover some alerts around the reconnaissance phase. From there, we'll piece together what's happening and how we can respond.
Let's start with some alerts we might see as an attack ensues, and what they might mean. In Figure 7.30, we see the beginning of some reconnaissance. Network mapping reconnaissance, for example, is a method to map out the environment and build out a knowledge base for later use. In the following example, we see srv2012r2
appears to be requesting some suspicious DNS queries from...