Files
splunk-security_content/response_phases/detection_analysis.yml
2021-02-08 10:21:38 -05:00

34 lines
1.3 KiB
YAML

author: ButterCup, Splunk
date: '2020-07-17'
description: Events are occurances of a systems or systems. Incidents are declared
violations and incidents can occur in countless ways. Detection and analysis phase
is about identifying an event as an incident and properly categorizing and prioritizing
incident notification and documentation. It is infeasible to develop step-by-step
instructions for handling every incident. This generic detection and analysis process
is a template to ensure the right process is being followed.
id: a6eec2aa-3ec8-4f16-9c09-b8537873047d
name: Detection and Analysis
references:
- 3.2 Detection and Analysis - https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-61r2.pdf
response_task:
- id: 92ba5c50-717d-44e7-bb88-72bf6907ec83
name: Determine if an incident has occurred
- id: ef9e7a25-73f0-4b63-b43b-2f4171518931
name: Analyze precursors to the event
- id: 994298f0-75fc-4c14-b044-9b81944d3a03
name: Confirm Incident
- id: 91f1c863-c080-4b3c-921c-e1ca1c0e7ae1
name: Determine incident prioritization
- id: 3890e0b3-bb46-4b9b-8134-184dbe644a8a
name: Document and Notify of Incident
sla: null
sla_type: minutes
tags:
analytic_story: NIST SP 800-61r2 Response Plan
nist: RS.RP
product:
- Splunk Phantom
usecase: Advanced Threat Detection
type: response
version: 1