Files
splunk-security_content/response_phases/identification.yml
divious1 339e117806 skeleton
2020-08-25 18:56:44 -04:00

32 lines
1.6 KiB
YAML

name: Identification
id: 6cdd56ba-5ffd-46a9-9dde-d25ce755c100
sla_type: minutes
sla:
description: Events are occurances of a systems or systems. Incidents are declared violations and incidents can occur in countless ways. Detection and analysis phase is about identifying an event as an incident and properly categorizing and prioritizing incident notification and documentation. It is infeasible to develop step-by-step instructions for handling every incident. This generic detection and analysis process is a template to ensure the right process is being followed.
references:
- 3.2 Detection and Analysis - https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-61r2.pdf
response_task:
- id: 92ba5c50-717d-44e7-bb88-72bf6907ec83
name: Determine if an incident has occurred
- id: ef9e7a25-73f0-4b63-b43b-2f4171518931
name: Analyze precursors to the event
- id: be7cce5c-29b9-405c-923a-d4565705da2e
name: Analyze host indicator and reputation
- id: a194130b-f5a8-4bfe-b09f-35f58f4397d5
name: Analyze IP address indicator and reputation
- id: 7744864c-5446-47ab-8118-4cbaa1649747
name: Analyze domain indicator and reputation
- id: 65a23d95-7b5a-405c-b5bf-893983478d35
name: Analyze url indicator and reputation
- id: 9e2d3e51-2e8f-4d49-8206-fb3e5fbf6620
name: Analyze email indicator and reputation
- id: 994298f0-75fc-4c14-b044-9b81944d3a03
name: Confirm Incident
- id: 91f1c863-c080-4b3c-921c-e1ca1c0e7ae1
name: Determine incident prioritization
- id: 3890e0b3-bb46-4b9b-8134-184dbe644a8a
name: Document and Notify of Incident
date: '2020-07-17'
version: 1
author: ButterCup, Splunk