author: ButterCup date: '2020-07-30' description: The containment phase is for the acquiring, preserving, securing, and documenting of evidence that leads to the appropriate containment or mititgation of the incident. This phase will identify additional hosts and known vulnerabilities and implememt monitoring of the containment. id: 5d790fae-8ba6-4fc9-b288-78b67ef8370c name: Containment references: - 3.3 Containment, Eradication, and Recovery - https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-61r2.pdf response_task: - id: 3d481dd1-4f30-4262-a846-78af6bdce11c name: identify_additional_affected_hosts - id: 735335a5-7ac0-4bdf-b1d3-6f4a6767d02f name: contain_incident - id: edb7867c-2e81-4356-a422-92781f4fa34c name: implement_additional_monitoring - id: f28177ae-78de-43c9-8692-e972e8a0aa62 name: identify_vunlerabilities sla: null sla_type: minutes tags: analytic_story: NIST SP 800-61r2 Response Plan nist: RS.RP product: - Splunk Phantom usecase: Advanced Threat Detection type: response version: 2