Files
2021-02-08 10:21:38 -05:00

44 lines
1.7 KiB
YAML

author: ButterCup, Splunk
date: '2020-07-17'
description: Events are occurances of a systems or systems. Incidents are declared
violations and incidents can occur in countless ways. Detection and analysis phase
is about identifying an event as an incident and properly categorizing and prioritizing
incident notification and documentation. It is infeasible to develop step-by-step
instructions for handling every incident. This generic detection and analysis process
is a template to ensure the right process is being followed.
id: 6cdd56ba-5ffd-46a9-9dde-d25ce755c100
name: Identification
references:
- 3.2 Detection and Analysis - https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-61r2.pdf
response_task:
- id: 92ba5c50-717d-44e7-bb88-72bf6907ec83
name: Determine if an incident has occurred
- id: ef9e7a25-73f0-4b63-b43b-2f4171518931
name: Analyze precursors to the event
- id: be7cce5c-29b9-405c-923a-d4565705da2e
name: Analyze host indicator and reputation
- id: a194130b-f5a8-4bfe-b09f-35f58f4397d5
name: Analyze IP address indicator and reputation
- id: 7744864c-5446-47ab-8118-4cbaa1649747
name: Analyze domain indicator and reputation
- id: 65a23d95-7b5a-405c-b5bf-893983478d35
name: Analyze url indicator and reputation
- id: 9e2d3e51-2e8f-4d49-8206-fb3e5fbf6620
name: Analyze email indicator and reputation
- id: 994298f0-75fc-4c14-b044-9b81944d3a03
name: Confirm Incident
- id: 91f1c863-c080-4b3c-921c-e1ca1c0e7ae1
name: Determine incident prioritization
- id: 3890e0b3-bb46-4b9b-8134-184dbe644a8a
name: Document and Notify of Incident
sla: null
sla_type: minutes
tags:
analytic_story: NIST SP 800-61r2 Response Plan
nist: RS.RP
product:
- Splunk Phantom
usecase: Advanced Threat Detection
type: response
version: 1