mirror of
https://github.com/splunk/security_content
synced 2026-06-08 17:32:49 +00:00
32 lines
1.6 KiB
YAML
32 lines
1.6 KiB
YAML
name: Identification
|
|
id: 6cdd56ba-5ffd-46a9-9dde-d25ce755c100
|
|
sla_type: minutes
|
|
sla:
|
|
description: Events are occurances of a systems or systems. Incidents are declared violations and incidents can occur in countless ways. Detection and analysis phase is about identifying an event as an incident and properly categorizing and prioritizing incident notification and documentation. It is infeasible to develop step-by-step instructions for handling every incident. This generic detection and analysis process is a template to ensure the right process is being followed.
|
|
references:
|
|
- 3.2 Detection and Analysis - https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-61r2.pdf
|
|
response_task:
|
|
- id: 92ba5c50-717d-44e7-bb88-72bf6907ec83
|
|
name: Determine if an incident has occurred
|
|
- id: ef9e7a25-73f0-4b63-b43b-2f4171518931
|
|
name: Analyze precursors to the event
|
|
- id: be7cce5c-29b9-405c-923a-d4565705da2e
|
|
name: Analyze host indicator and reputation
|
|
- id: a194130b-f5a8-4bfe-b09f-35f58f4397d5
|
|
name: Analyze IP address indicator and reputation
|
|
- id: 7744864c-5446-47ab-8118-4cbaa1649747
|
|
name: Analyze domain indicator and reputation
|
|
- id: 65a23d95-7b5a-405c-b5bf-893983478d35
|
|
name: Analyze url indicator and reputation
|
|
- id: 9e2d3e51-2e8f-4d49-8206-fb3e5fbf6620
|
|
name: Analyze email indicator and reputation
|
|
- id: 994298f0-75fc-4c14-b044-9b81944d3a03
|
|
name: Confirm Incident
|
|
- id: 91f1c863-c080-4b3c-921c-e1ca1c0e7ae1
|
|
name: Determine incident prioritization
|
|
- id: 3890e0b3-bb46-4b9b-8134-184dbe644a8a
|
|
name: Document and Notify of Incident
|
|
date: '2020-07-17'
|
|
version: 1
|
|
author: ButterCup, Splunk
|