Incident investigation essentials
Security incident management is the process of identifying, managing, recording, and analyzing security threats or incidents in real time. Incident investigation is a part of the Incident Response (IR) process where Security Operations Center (SOC) teams scan, control, check, and investigate after a breach occurs within an organization. It is a systematic process to find the root causes of problems and develop effective solutions.
Identification
The first step of investigation is identification, particularly noticing indicators of compromise that could suggest a malicious presence in your system. In all major platforms, five key areas that might be good indicators of compromise are as follows.
Suspicious processes
There might be suspicious processes running on servers or end-user computers that could indicate possible compromise. Some of the signs that there are malicious processes include the following:
- Odd names: A process...