Files
splunk-security_content/response_phases/containment.yml
2021-02-08 10:21:38 -05:00

30 lines
1.0 KiB
YAML

author: ButterCup
date: '2020-07-30'
description: The containment phase is for the acquiring, preserving, securing, and
documenting of evidence that leads to the appropriate containment or mititgation
of the incident. This phase will identify additional hosts and known vulnerabilities
and implememt monitoring of the containment.
id: 5d790fae-8ba6-4fc9-b288-78b67ef8370c
name: Containment
references:
- 3.3 Containment, Eradication, and Recovery - https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-61r2.pdf
response_task:
- id: 3d481dd1-4f30-4262-a846-78af6bdce11c
name: identify_additional_affected_hosts
- id: 735335a5-7ac0-4bdf-b1d3-6f4a6767d02f
name: contain_incident
- id: edb7867c-2e81-4356-a422-92781f4fa34c
name: implement_additional_monitoring
- id: f28177ae-78de-43c9-8692-e972e8a0aa62
name: identify_vunlerabilities
sla: null
sla_type: minutes
tags:
analytic_story: NIST SP 800-61r2 Response Plan
nist: RS.RP
product:
- Splunk Phantom
usecase: Advanced Threat Detection
type: response
version: 2