mirror of
https://github.com/splunk/security_content
synced 2026-06-08 17:32:49 +00:00
44 lines
1.7 KiB
YAML
44 lines
1.7 KiB
YAML
author: ButterCup, Splunk
|
|
date: '2020-07-17'
|
|
description: Events are occurances of a systems or systems. Incidents are declared
|
|
violations and incidents can occur in countless ways. Detection and analysis phase
|
|
is about identifying an event as an incident and properly categorizing and prioritizing
|
|
incident notification and documentation. It is infeasible to develop step-by-step
|
|
instructions for handling every incident. This generic detection and analysis process
|
|
is a template to ensure the right process is being followed.
|
|
id: 6cdd56ba-5ffd-46a9-9dde-d25ce755c100
|
|
name: Identification
|
|
references:
|
|
- 3.2 Detection and Analysis - https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-61r2.pdf
|
|
response_task:
|
|
- id: 92ba5c50-717d-44e7-bb88-72bf6907ec83
|
|
name: Determine if an incident has occurred
|
|
- id: ef9e7a25-73f0-4b63-b43b-2f4171518931
|
|
name: Analyze precursors to the event
|
|
- id: be7cce5c-29b9-405c-923a-d4565705da2e
|
|
name: Analyze host indicator and reputation
|
|
- id: a194130b-f5a8-4bfe-b09f-35f58f4397d5
|
|
name: Analyze IP address indicator and reputation
|
|
- id: 7744864c-5446-47ab-8118-4cbaa1649747
|
|
name: Analyze domain indicator and reputation
|
|
- id: 65a23d95-7b5a-405c-b5bf-893983478d35
|
|
name: Analyze url indicator and reputation
|
|
- id: 9e2d3e51-2e8f-4d49-8206-fb3e5fbf6620
|
|
name: Analyze email indicator and reputation
|
|
- id: 994298f0-75fc-4c14-b044-9b81944d3a03
|
|
name: Confirm Incident
|
|
- id: 91f1c863-c080-4b3c-921c-e1ca1c0e7ae1
|
|
name: Determine incident prioritization
|
|
- id: 3890e0b3-bb46-4b9b-8134-184dbe644a8a
|
|
name: Document and Notify of Incident
|
|
sla: null
|
|
sla_type: minutes
|
|
tags:
|
|
analytic_story: NIST SP 800-61r2 Response Plan
|
|
nist: RS.RP
|
|
product:
|
|
- Splunk Phantom
|
|
usecase: Advanced Threat Detection
|
|
type: response
|
|
version: 1
|