Summary
In this chapter, we covered the basic concepts of digital forensics and incident response and learned the difference between events and incidents. We also learned the concept of digital evidence and the importance of forensic artifacts. We identified the differences between IoCs and IoAs. This will be very useful for conducting forensic investigations and identifying the persistence of a threat actor.
We reviewed three of the most important frameworks and guidelines regarding incident response and digital forensics and learned the importance of defining an incident response strategy.
In the next chapter, we will learn how to perform first-response procedures and collect evidence using triage.