mirror of
https://github.com/splunk/security_content
synced 2026-06-08 17:32:49 +00:00
30 lines
1.0 KiB
YAML
30 lines
1.0 KiB
YAML
author: ButterCup
|
|
date: '2020-07-30'
|
|
description: The containment phase is for the acquiring, preserving, securing, and
|
|
documenting of evidence that leads to the appropriate containment or mititgation
|
|
of the incident. This phase will identify additional hosts and known vulnerabilities
|
|
and implememt monitoring of the containment.
|
|
id: 5d790fae-8ba6-4fc9-b288-78b67ef8370c
|
|
name: Containment
|
|
references:
|
|
- 3.3 Containment, Eradication, and Recovery - https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-61r2.pdf
|
|
response_task:
|
|
- id: 3d481dd1-4f30-4262-a846-78af6bdce11c
|
|
name: identify_additional_affected_hosts
|
|
- id: 735335a5-7ac0-4bdf-b1d3-6f4a6767d02f
|
|
name: contain_incident
|
|
- id: edb7867c-2e81-4356-a422-92781f4fa34c
|
|
name: implement_additional_monitoring
|
|
- id: f28177ae-78de-43c9-8692-e972e8a0aa62
|
|
name: identify_vunlerabilities
|
|
sla: null
|
|
sla_type: minutes
|
|
tags:
|
|
analytic_story: NIST SP 800-61r2 Response Plan
|
|
nist: RS.RP
|
|
product:
|
|
- Splunk Phantom
|
|
usecase: Advanced Threat Detection
|
|
type: response
|
|
version: 2
|